Yaamlabs

Threat intel

Integrity Tech mail theft: what to check in Microsoft 365

Seven countries say Integrity Tech operators sprayed Exchange and Microsoft 365 passwords and copied mailboxes. The sign-in, audit and app checks to run.

On October 8, the FBI, CISA and NSA, together with agencies from the UK, Australia, Canada, Japan, New Zealand and Spain, published joint advisory AA26-281A on threat actors enabled by Integrity Technology Group, a Beijing company the US Treasury sanctioned in January 2025 and the UK in December 2025. The FBI says it recovered an archived email database from these operators, and that victims of email theft included government organisations, law enforcement agencies, healthcare systems and religious institutions in Southeast Asia. The advisory also lists targets in US critical infrastructure, US law enforcement, education and religious organisations, and organisations in Africa and North America.

Much of the advisory is about mail. The actors guessed and sprayed passwords against Microsoft 365 and on-premises Exchange, read mailboxes through Exchange Web Services (EWS) and through app credentials, and ran a web application that gives third parties access to the stolen mail. If your organisation runs Exchange or Microsoft 365 and has accounts that still sign in with a password alone, this activity applies to you. Our earlier post covers the domain seizures, the scanning tools and the old CVEs in the same advisory. The checks below focus on the mailbox side and what to look for in your tenant.

How it works

For mail, the way in is password guessing. The advisory names EBurst, an open source Python tool, which tries passwords against each supplied mailbox through every Exchange interface it can reach: Exchange Control Panel (ECP), EWS, the Offline Address Book (OAB), Outlook on the web (OWA), RPC, the Exchange API, MAPI, PowerShell, Autodiscover and ActiveSync. Password spraying means trying one or two common passwords across many accounts, which stays under per-account lockout thresholds. The agencies tell defenders to cover all of these interfaces, since protecting OWA alone leaves the other nine open.

Once a password works, three collection paths appear in the advisory. Curlc4.txt is a PHP bot that talks to the EWS API to pull mail, calendars and contacts, compresses them, sometimes encrypts them with RC4 or AES-128-CBC, and uploads them to natcloudservice[.]com. The FBI says the script runs stand-alone rather than on a compromised machine, so to the mail server it looks like a remote client logging in. Office-cli is a Linux command-line tool that reads Microsoft 365 mailboxes using a client_id, tenant_id and secret from JSON files in its config directory, saving results under a dump directory. That is how an app registration authenticates to Microsoft Graph, so the traffic looks like an ordinary integration. The operators also pulled mail by hand and downloaded databases.

What attackers are doing

The advisory dates initial access to at least mid-January 2021. It gives no date for any single theft and no count of victims, and it does not name the affected countries in Southeast Asia. The FBI says office-cli was used to keep pulling mail "across different time periods", and that the operators updated the accounts it used, swapping in the most recent ones.

Stolen mail was staged with file names chosen to avoid notice, including 001.gif, Css.js, Include.png, M2k.js, M2k_list.js and M2k_ui_adm.js, to hide what the advisory calls a MySQL email dump. The operators maintain a custom web application where users pass arguments in the URL to read the mail of specific accounts. The advisory says this gives third parties access to the stolen content but does not say who they are. In some cases, access to the exfiltrated data was restricted to IP addresses in Xiamen, China.

The UK National Cyber Security Centre (NCSC), in its announcement, says the actors are using AI tools such as automated scanning alongside large-scale botnets. As The Hacker News points out, the advisory text itself does not mention AI.

What to do

1. Require MFA and close password-only paths

The advisory asks for multifactor authentication (MFA) on all services, naming webmail first. In Microsoft Entra ID, create a Conditional Access policy that requires MFA for all users on all cloud apps, and a second one from the "Block legacy authentication" template, which blocks clients that cannot do MFA. Microsoft has already removed Basic authentication from Exchange Online for EWS, ActiveSync, POP, IMAP, Autodiscover, OAB and remote PowerShell, with SMTP AUTH the main exception. On-premises Exchange still accepts passwords on these endpoints unless you configure otherwise, so put OWA, ECP and EWS behind a gateway that enforces MFA, and turn off protocols a mailbox does not need with Set-CASMailbox.

2. Look for spraying in the sign-in logs

In the Entra admin center, open Sign-in logs and filter on failures. Error 50126 (invalid username or password) spread across many users from a few IP addresses is the signature of spraying, and 50053 means Smart Lockout blocked the account. Then take the source IPs and look for any successful sign-in from them, especially single-factor ones. For on-premises Exchange, review IIS logs under C:\inetpub\logs\LogFiles\W3SVC1 for one address failing against many mailboxes on /EWS, /Autodiscover, /Microsoft-Server-ActiveSync, /owa, /ecp, /mapi and /OAB.

3. Check the apps that can read mail

In Entra ID, list app registrations and enterprise applications holding the Microsoft Graph Mail.Read or Mail.ReadWrite application permission, or the EWS full_access_as_app permission, and check who added each one and when its secrets were last created. The Service principal sign-ins tab of the sign-in logs shows when these apps authenticate and from which IP address. Remove what nobody owns, and use RBAC for Applications in Exchange Online to limit the apps you keep to the mailboxes they actually need. Microsoft now recommends this over the older application access policies.

4. Search the audit log for mailbox reads and exports

In Microsoft Purview Audit, search for MailItemsAccessed events on sensitive mailboxes. Since 2024 Microsoft has been extending this event to Audit (Standard) tenants, but for Standard licences an administrator has to confirm it is in each mailbox's audit set, and events are not logged retroactively. Look for access by app IDs or client IP addresses you do not recognise, and for large bursts of reads. On-premises, a mailbox export uses New-MailboxExportRequest, which needs the Mailbox Import Export role. Check who holds that role, and search PowerShell script block logs (event 4104) and the admin audit log for the cmdlet.

5. If you find a match

Reset the password of each affected account and revoke its sessions, then confirm MFA is registered by the real user. Delete unknown app secrets or the whole app registration, and review mailbox delegate permissions. Block natcloudservice[.]com and 149.28.132[.]137, and search proxy and firewall logs for earlier connections to them and servers for the staging file names above. The advisory asks you to isolate and scope before you remove anything, and to report to your national agency.

The wider lesson

None of the mail collection described here needed a software flaw. A sprayed password, an EWS endpoint that accepts it and an app with Mail.Read were enough. Each of those shows up in the sign-in, app permission and audit checks above, so they belong on a quarterly review schedule.

Our security operations team can run the sign-in, app permission and audit log hunts above in your tenant, and our safeguarding and hardening work closes legacy protocols and app permissions you do not need. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: CISA advisory AA26-281A, Advisory PDF on IC3, NCSC announcement, The Hacker News, UK sanctions notice, 9 December 2025, Microsoft: deprecation of Basic authentication in Exchange Online, Microsoft: RBAC for Applications in Exchange Online, Office 365 for IT Pros on MailItemsAccessed, Elastic: Entra ID excessive account lockouts, Elastic: Exchange mailbox export via PowerShell.

Back to the blog, or read this post on the full site.