Integrity Technology Group: commercial infrastructure for PRC cyber operations
Date: 17 August 2026Subject: Integrity Technology Group / 永信至诚科技集团股份有限公司Scope: Leaked contracts, 2026-8-17 18:45:43 Author: krypt3ia.wordpress.com(查看原文) 阅读量:64 收藏

Date: 17 August 2026
Subject: Integrity Technology Group / 永信至诚科技集团股份有限公司
Scope: Leaked contracts, technical documentation, personnel data, financial records, exercise material, and reconnaissance artifacts reviewed to date

Assessment

The Integrity Technology Group leak from February 2026 on DarkForums, exposes a commercial cybersecurity company with capabilities directly relevant to state cyber operations. The files document APT intelligence collection and adversary modeling. They also show offensive exercise teams, cyber-range development, enterprise and industrial-control simulation, military customers, and work with major Chinese energy organizations.

The evidence does not show a PLA order directing Integrity to compromise a foreign target. It does show however, that Integrity had the personnel, technical infrastructure, and customer relationships needed to support cyber force development outside a military organization. Several elements were already visible in Chinese corporate filings and Western reporting on Flax Typhoon. The leaked records add internal detail: named personnel, offensive exercise results, IT/OT range specifications, PLA financial relationships, and contract payments.

JudgmentConfidence
Integrity maintained mature cyber-range, threat-intelligence, offensive-security, and IT/OT simulation capabilities.High
Integrity had recurring commercial relationships with multiple PLA organizations.High
Integrity personnel could conduct multi-stage network intrusions in authorized attack-defense exercises.High
Integrity had sustained access to Chinese energy-sector defensive and simulation environments.High
Integrity’s capabilities could support PLA cyber force development without residing inside a military organization.Moderate
The uploaded files prove PLA tasking of Integrity for unauthorized foreign intrusions.Not established

Attack-team records show a practiced intrusion capability

A cybersecurity attack-defense exercise registration sheet identifies Integrity Technology Group as the participating organization and marks its role as 攻击方, the attack side. Four employees are listed as network security engineers. The associated attack-team report records successful compromises against several exercise targets. It is a results document, not a proposal or product description.

Against Fuma Long Group, the team reported weak-password access to a FastGPT platform and a digital-factory system. It also described abuse of a password-reset weakness in a smart-cloud platform, access to more than 14,000 records, and control associated with 15,896 device nodes. Against SKSHU Paint, the report claims exploitation of a Shopex remote-code-execution vulnerability, followed by access to the management intranet, database privileges, and shell access.

Fuma Pentest Report

The Fujian Boss Software section is more detailed. The team used a Weaver e-cology SQL-injection flaw to obtain database administrator privileges. It separately documented arbitrary file upload against a Kingdee Cloud application and a webshell running with SYSTEM privileges. The report then lists access to internal MySQL, Oracle, Redis, SSH, and FTP services and records movement from the first compromised subnet into additional internal network segments.

Pg 7 of Report on Fujian Boss

The exercise was authorized, so these intrusions should not be characterized as malicious operations. The capability demonstrated is still clear: Integrity personnel could move from application access into privileged execution, database compromise, webshell deployment, internal discovery, and network expansion.

Unit 78021 ties a PLA contract to actual payment

The PLA Unit 78021 material is the strongest financial case in the collection because the contract and bank records reconcile. The procurement agreement identifies 中国人民解放军78021部队, PLA Unit 78021, as the purchaser of a special-purpose equipment procurement and management system from Integrity. The provisional value is RMB 1.885 million. The agreement includes military procurement, labeling, coding, security, acceptance, and performance-bond requirements. Total receipts from the unit during the ledger period reach approximately RMB 2.95 million.

The first transaction directly validates the payment schedule in the leaked contract. The later payments exceed the remaining value of that procurement and should not be assigned to it without supporting records. They point instead to additional Unit 78021 business missing from the current document set. The wider ledger contains 52 incoming transactions from 22 counterparties whose names explicitly identify them as PLA organizations. Those payments total approximately RMB 20.91 million during the one-year period covered by the ledger.

The largest named military counterparties include Unit 32087 Support Department, Unit 78021, Unit 32047, Unit 61770, Unit 32057, and the PLA Network Space Force Information Engineering University. The transaction descriptions do not identify what every unit purchased. The financial evidence is still sufficient to show that Integrity’s military business was broader than the single Unit 78021 contract.

Cyber ranges were a core technical capability

The personnel data identifies 51 employees assigned to the Chunqiu Yunjing cyber-range product line. Other technical personnel sit inside the Third Legion, Special Industry Business Cluster, including the Chunqiu Yundun R&D Center, Network Data Intelligence R&D Department, DPOC, A0x34, K0x33, and custom R&D functions.

Several of those internal labels have little public footprint and are useful pivots for further collection. The National Energy Group contract gives a concrete view of Integrity’s range capability. The 2025 agreement covers a Group Cybersecurity Range Construction Project worth RMB 6.6788 million. Delivery is to the National Energy Group Data Center C2 cyber-range server room and range in Beijing.

The equipment list includes ordinary servers and security appliances alongside IT/OT data-collection technology, attack monitoring, malware and code-execution monitoring, industrial-process simulation, and a thermal-power DCS operation simulation system. The specifications refer to DCS and PLC control data, analog and digital signals, network behavior, and industrial process information.

The contract shows that Integrity could build environments that went well beyond web application training. It could reproduce parts of the technical environment found in power generation and industrial control. Nothing in the document identifies a military user for this particular range.

Three Gorges gave Integrity direct exposure to critical-infrastructure defense

The 2021 Three Gorges Group contract places Integrity inside another strategically important energy environment. The work supported the national cybersecurity attack-defense exercise involving China Three Gorges Group. The protected scope included data centers in Beijing, Yichang, and Chengdu, along with major power-generation organizations and other key units.

Integrity’s responsibilities covered threat-intelligence collection, traffic monitoring, attack analysis, malware analysis, vulnerability analysis, incident response, tracing, and technical reporting. The pricing appendix specifies 30 person-days at RMB 5,000 per person-day, for a total of RMB 150,000. That should not be read as 30 calendar days. The contract is small compared with other projects in the collection, but its value lies in the environment. Three Gorges exposed Integrity to the defensive architecture and operational requirements of a major Chinese energy operator.

The financial records show that this was part of a wider energy-sector practice. A narrow search for counterparties with explicit electricity, grid, energy, or generation terms identified about RMB 12.38 million in incoming payments during the ledger period. Named customers include State Grid Zhejiang Electric Power, China Southern Power Grid organizations, Guangxi Power Grid, and power research institutes.

The APT platform organized adversary knowledge for reuse

Integrity’s APT Adversary Tracking System Product White Paper describes a platform for collecting reports from commercial vendors as well as Chinese security companies and open repositories. Named sources include FireEye and CrowdStrike along with Symantec and Kaspersky. Chinese sources include 360 plus Qi An Xin and Antiy. The system also draws from APTnotes and Threat-Hunting. The platform extracts IP addresses and domains as well as hashes and URLs. It also identifies email addresses and CVEs along with registry artifacts and file information. The resulting data is organized into structured APT profiles and TTP records.

APT Adversary Tracking System Product White Paper”
Version V3.0.20200416, dated June 2020

MITRE ATT&CK provided the basis for the behavior model, with Integrity adding its own tactical categories, scenario logic, and temporal analysis. The white paper describes roughly 12 tactical categories and more than 200 technical methods. The document presents this as threat intelligence and defensive analysis. It does not show PLA use of the platform.

Click for larger view

Its significance comes from what existed elsewhere in the same company: offensive personnel and a range business capable of reproducing network environments. The current files do not show whether those functions were formally joined.

MITRE ATT&CK serves as the foundation for Integrity’s adversary-behavior model, but the white paper does not simply reproduce the ATT&CK matrix. Integrity describes adapting it into a localized TTP framework built around approximately 12 tactical categories and more than 200 technical methods, with relationships between tactics and techniques represented as a matrix rather than as isolated indicators. The system also adds time and scenario dimensions to the model.

Integrity featureOutside-China baseline circa 2020Assessment
12 ATT&CK tactical objectivesStandard Enterprise ATT&CK structureNot an innovation
200+ “technical methods”ATT&CK already had hundreds of techniques/sub-techniquesCannot establish greater granularity
Chinese “localization” of techniquesATT&CK was already extensible and commonly adaptedLocalization rather than fundamental innovation
Time dimension for individual APTsPossible through external analysis, but not a primary ATT&CK dimensionMeaningful analytic extension
Scenario dimensionATT&CK already supported procedures and techniques under multiple tacticsProductized extension rather than new concept
IOC ↔ APT ↔ TTP relationshipsAvailable through external TIPs and standardsIntegration is notable, concept is not unique
Executable/testable technical checkpointsAtomic Red Team, CALDERA, and MITRE emulation work already existedParallel development, but tightly integrated here
Automatic report ingestion and IOC extractionCommon TIP functionalityConventional
Proprietary data modelSTIX/TAXII and MISP already supported structured sharingLess interoperable than external standards
Explicit military/tactical framingMITRE generally framed ATT&CK as adversary knowledge and threat-informed defenseDistinctive Chinese framing

This allows analysts to compare how the same APT changes its techniques over time, distinguish differences between actors using similar methods, and record how a technique is implemented in a particular operational setting. The white paper uses Duqu as an example, showing how differences between Duqu activity observed in 2011 and Duqu 2.0 in 2015 can be represented as changes in the actor’s TTP profile. It also describes linking individual techniques to technically testable security controls, giving the platform utility for adversary emulation, security validation, and attack-defense exercise design. The document presents these functions as threat-intelligence analysis and defensive assessment. It does not identify a PLA customer for the platform or show that its ATT&CK-derived models were used to support military operations.

The special-industry structure may contain the most sensitive technical work

The personnel roster contains 471 records in the copy reviewed. A large part of the organization uses the label 特种行业, special industry. The roster contains 116 personnel whose organizational path includes the term. Within that structure are 15 people assigned to A0x34, 14 to Network Data Intelligence R&D, 10 to DPOC, seven to K0x33, and additional staff in custom R&D, solutions, marketing, and the Chunqiu Yundun R&D Center.

Personnel Roster CSV

The personnel file does not define “special industry,” and the term should not be translated automatically into military or intelligence work. The military and public-security customer base makes the internal structure worth closer attention. A0x34, K0x33, DPOC, and Network Data Intelligence R&D are the better collection pivots because they are more specific and may surface technical documentation tied to particular projects.

Wuyi Jiayu extends the same customer and technical ecosystem

The leak repeatedly exposes Beijing Wuyi Jiayu Technology alongside Integrity. The financial records show direct intercompany movement. On 22 October 2024, the Wuyi account transferred RMB 40 million to Integrity. The outgoing Wuyi entry and incoming Integrity entry match in amount and occur one second apart.

Group Transaction Receipts and Payments Records csv

The same ledger shows Wuyi receiving payments directly from PLA and public-security organizations. The invoice material provides a clean customer-payment chain. Wuyi issued an invoice to the Beijing Applied Science and Technology Research Institute on 20 December 2024 for RMB 1.145 million in technical services.

A separate verification record confirms the invoice details. Six days later, the financial ledger records a payment from the institute into the Wuyi account for exactly RMB 1.145 million. Personnel carried under Wuyi also appear inside Integrity technical organizations, including Network Data Intelligence R&D, DPOC, the AR Laboratory, and cyber-range functions.

Public corporate filings already identify Wuyi as an Integrity subsidiary. The leak shows how closely the personnel and financial structures overlap in practice. For collection purposes, searches limited to the parent company’s legal name will miss part of the picture.

Collection priorities

The next useful documents are the ones that connect customers to technical work. The unexplained Unit 78021 payments are the clearest starting point. The known contract explains only part of the money received from the unit. Contracts, invoices, acceptance reports, or technical annexes tied to the remaining payments could reveal additional projects.

The same approach should be applied to other repeat PLA counterparties, especially Units 32087, 32047, 61770, and 32057. Internally, priority should go to A0x34, K0x33, DPOC, Network Data Intelligence R&D, and Chunqiu Yundun R&D Center. Project records tied to those units may clarify what Integrity meant by “special industry” and which customers received their work.

Cyber-range scenario files would be particularly valuable. Target templates, scoring records, red-team tasking, exercise plans, or industrial-control scenarios could show whether military customers used Integrity ranges for operator training or mission rehearsal. The APT platform presents a similar gap. Customer records, exports, actor profiles, or scenario packages would help determine whether threat intelligence was used only for analysis or also fed training and exercise development.

The reconnaissance corpus needs sector-level review rather than isolated interpretation. Repeated collection against Taiwan government, defense, telecom, research, or civil-society targets would carry more weight than any single crawl file.

Conclusion

The uploaded records show Integrity operating across offensive security and threat intelligence. They also show work in cyber ranges and industrial simulation. Other records document military procurement and critical-infrastructure defense. The Unit 78021 material provides the strongest financial corroboration. The attack-team report offers the clearest evidence of hands-on offensive skill. The National Energy Group contract shows the depth of the company’s IT/OT simulation capability. The Three Gorges material establishes direct work inside a major energy-defense environment.

These findings place Integrity in a position to support PRC cyber force development through commercial expertise and infrastructure. The main gap is operational. The current files do not show a PLA tasking chain linking Integrity personnel to ranges or intelligence systems used in a foreign intrusion. Establishing that link or determining that it did not exist remains the central collection requirement.


文章来源: https://krypt3ia.wordpress.com/2026/08/17/integrity-technology-group-commercial-infrastructure-for-prc-cyber-operations/
如有侵权请联系:admin#unsafe.sh