Date: 17 August 2026
Subject: Integrity Technology Group / 永信至诚科技集团股份有限公司
Scope: Leaked contracts, technical documentation, personnel data, financial records, exercise material, and reconnaissance artifacts reviewed to date
The Integrity Technology Group leak from February 2026 on DarkForums, exposes a commercial cybersecurity company with capabilities directly relevant to state cyber operations. The files document APT intelligence collection and adversary modeling. They also show offensive exercise teams, cyber-range development, enterprise and industrial-control simulation, military customers, and work with major Chinese energy organizations.
The evidence does not show a PLA order directing Integrity to compromise a foreign target. It does show however, that Integrity had the personnel, technical infrastructure, and customer relationships needed to support cyber force development outside a military organization. Several elements were already visible in Chinese corporate filings and Western reporting on Flax Typhoon. The leaked records add internal detail: named personnel, offensive exercise results, IT/OT range specifications, PLA financial relationships, and contract payments.
| Judgment | Confidence |
|---|---|
| Integrity maintained mature cyber-range, threat-intelligence, offensive-security, and IT/OT simulation capabilities. | High |
| Integrity had recurring commercial relationships with multiple PLA organizations. | High |
| Integrity personnel could conduct multi-stage network intrusions in authorized attack-defense exercises. | High |
| Integrity had sustained access to Chinese energy-sector defensive and simulation environments. | High |
| Integrity’s capabilities could support PLA cyber force development without residing inside a military organization. | Moderate |
| The uploaded files prove PLA tasking of Integrity for unauthorized foreign intrusions. | Not established |
A cybersecurity attack-defense exercise registration sheet identifies Integrity Technology Group as the participating organization and marks its role as 攻击方, the attack side. Four employees are listed as network security engineers. The associated attack-team report records successful compromises against several exercise targets. It is a results document, not a proposal or product description.

Against Fuma Long Group, the team reported weak-password access to a FastGPT platform and a digital-factory system. It also described abuse of a password-reset weakness in a smart-cloud platform, access to more than 14,000 records, and control associated with 15,896 device nodes. Against SKSHU Paint, the report claims exploitation of a Shopex remote-code-execution vulnerability, followed by access to the management intranet, database privileges, and shell access.
Fuma Pentest Report
The Fujian Boss Software section is more detailed. The team used a Weaver e-cology SQL-injection flaw to obtain database administrator privileges. It separately documented arbitrary file upload against a Kingdee Cloud application and a webshell running with SYSTEM privileges. The report then lists access to internal MySQL, Oracle, Redis, SSH, and FTP services and records movement from the first compromised subnet into additional internal network segments.
Pg 7 of Report on Fujian Boss
The exercise was authorized, so these intrusions should not be characterized as malicious operations. The capability demonstrated is still clear: Integrity personnel could move from application access into privileged execution, database compromise, webshell deployment, internal discovery, and network expansion.
The PLA Unit 78021 material is the strongest financial case in the collection because the contract and bank records reconcile. The procurement agreement identifies 中国人民解放军78021部队, PLA Unit 78021, as the purchaser of a special-purpose equipment procurement and management system from Integrity. The provisional value is RMB 1.885 million. The agreement includes military procurement, labeling, coding, security, acceptance, and performance-bond requirements. Total receipts from the unit during the ledger period reach approximately RMB 2.95 million.
The first transaction directly validates the payment schedule in the leaked contract. The later payments exceed the remaining value of that procurement and should not be assigned to it without supporting records. They point instead to additional Unit 78021 business missing from the current document set. The wider ledger contains 52 incoming transactions from 22 counterparties whose names explicitly identify them as PLA organizations. Those payments total approximately RMB 20.91 million during the one-year period covered by the ledger.
The largest named military counterparties include Unit 32087 Support Department, Unit 78021, Unit 32047, Unit 61770, Unit 32057, and the PLA Network Space Force Information Engineering University. The transaction descriptions do not identify what every unit purchased. The financial evidence is still sufficient to show that Integrity’s military business was broader than the single Unit 78021 contract.
The personnel data identifies 51 employees assigned to the Chunqiu Yunjing cyber-range product line. Other technical personnel sit inside the Third Legion, Special Industry Business Cluster, including the Chunqiu Yundun R&D Center, Network Data Intelligence R&D Department, DPOC, A0x34, K0x33, and custom R&D functions.
Several of those internal labels have little public footprint and are useful pivots for further collection. The National Energy Group contract gives a concrete view of Integrity’s range capability. The 2025 agreement covers a Group Cybersecurity Range Construction Project worth RMB 6.6788 million. Delivery is to the National Energy Group Data Center C2 cyber-range server room and range in Beijing.
The equipment list includes ordinary servers and security appliances alongside IT/OT data-collection technology, attack monitoring, malware and code-execution monitoring, industrial-process simulation, and a thermal-power DCS operation simulation system. The specifications refer to DCS and PLC control data, analog and digital signals, network behavior, and industrial process information.
The contract shows that Integrity could build environments that went well beyond web application training. It could reproduce parts of the technical environment found in power generation and industrial control. Nothing in the document identifies a military user for this particular range.
The 2021 Three Gorges Group contract places Integrity inside another strategically important energy environment. The work supported the national cybersecurity attack-defense exercise involving China Three Gorges Group. The protected scope included data centers in Beijing, Yichang, and Chengdu, along with major power-generation organizations and other key units.
Integrity’s responsibilities covered threat-intelligence collection, traffic monitoring, attack analysis, malware analysis, vulnerability analysis, incident response, tracing, and technical reporting. The pricing appendix specifies 30 person-days at RMB 5,000 per person-day, for a total of RMB 150,000. That should not be read as 30 calendar days. The contract is small compared with other projects in the collection, but its value lies in the environment. Three Gorges exposed Integrity to the defensive architecture and operational requirements of a major Chinese energy operator.
The financial records show that this was part of a wider energy-sector practice. A narrow search for counterparties with explicit electricity, grid, energy, or generation terms identified about RMB 12.38 million in incoming payments during the ledger period. Named customers include State Grid Zhejiang Electric Power, China Southern Power Grid organizations, Guangxi Power Grid, and power research institutes.
Integrity’s APT Adversary Tracking System Product White Paper describes a platform for collecting reports from commercial vendors as well as Chinese security companies and open repositories. Named sources include FireEye and CrowdStrike along with Symantec and Kaspersky. Chinese sources include 360 plus Qi An Xin and Antiy. The system also draws from APTnotes and Threat-Hunting. The platform extracts IP addresses and domains as well as hashes and URLs. It also identifies email addresses and CVEs along with registry artifacts and file information. The resulting data is organized into structured APT profiles and TTP records.
APT Adversary Tracking System Product White Paper”
Version V3.0.20200416, dated June 2020
MITRE ATT&CK provided the basis for the behavior model, with Integrity adding its own tactical categories, scenario logic, and temporal analysis. The white paper describes roughly 12 tactical categories and more than 200 technical methods. The document presents this as threat intelligence and defensive analysis. It does not show PLA use of the platform.

Click for larger view
Its significance comes from what existed elsewhere in the same company: offensive personnel and a range business capable of reproducing network environments. The current files do not show whether those functions were formally joined.
MITRE ATT&CK serves as the foundation for Integrity’s adversary-behavior model, but the white paper does not simply reproduce the ATT&CK matrix. Integrity describes adapting it into a localized TTP framework built around approximately 12 tactical categories and more than 200 technical methods, with relationships between tactics and techniques represented as a matrix rather than as isolated indicators. The system also adds time and scenario dimensions to the model.
| Integrity feature | Outside-China baseline circa 2020 | Assessment |
|---|---|---|
| 12 ATT&CK tactical objectives | Standard Enterprise ATT&CK structure | Not an innovation |
| 200+ “technical methods” | ATT&CK already had hundreds of techniques/sub-techniques | Cannot establish greater granularity |
| Chinese “localization” of techniques | ATT&CK was already extensible and commonly adapted | Localization rather than fundamental innovation |
| Time dimension for individual APTs | Possible through external analysis, but not a primary ATT&CK dimension | Meaningful analytic extension |
| Scenario dimension | ATT&CK already supported procedures and techniques under multiple tactics | Productized extension rather than new concept |
| IOC ↔ APT ↔ TTP relationships | Available through external TIPs and standards | Integration is notable, concept is not unique |
| Executable/testable technical checkpoints | Atomic Red Team, CALDERA, and MITRE emulation work already existed | Parallel development, but tightly integrated here |
| Automatic report ingestion and IOC extraction | Common TIP functionality | Conventional |
| Proprietary data model | STIX/TAXII and MISP already supported structured sharing | Less interoperable than external standards |
| Explicit military/tactical framing | MITRE generally framed ATT&CK as adversary knowledge and threat-informed defense | Distinctive Chinese framing |
This allows analysts to compare how the same APT changes its techniques over time, distinguish differences between actors using similar methods, and record how a technique is implemented in a particular operational setting. The white paper uses Duqu as an example, showing how differences between Duqu activity observed in 2011 and Duqu 2.0 in 2015 can be represented as changes in the actor’s TTP profile. It also describes linking individual techniques to technically testable security controls, giving the platform utility for adversary emulation, security validation, and attack-defense exercise design. The document presents these functions as threat-intelligence analysis and defensive assessment. It does not identify a PLA customer for the platform or show that its ATT&CK-derived models were used to support military operations.
The personnel roster contains 471 records in the copy reviewed. A large part of the organization uses the label 特种行业, special industry. The roster contains 116 personnel whose organizational path includes the term. Within that structure are 15 people assigned to A0x34, 14 to Network Data Intelligence R&D, 10 to DPOC, seven to K0x33, and additional staff in custom R&D, solutions, marketing, and the Chunqiu Yundun R&D Center.

Personnel Roster CSV
The personnel file does not define “special industry,” and the term should not be translated automatically into military or intelligence work. The military and public-security customer base makes the internal structure worth closer attention. A0x34, K0x33, DPOC, and Network Data Intelligence R&D are the better collection pivots because they are more specific and may surface technical documentation tied to particular projects.
The leak repeatedly exposes Beijing Wuyi Jiayu Technology alongside Integrity. The financial records show direct intercompany movement. On 22 October 2024, the Wuyi account transferred RMB 40 million to Integrity. The outgoing Wuyi entry and incoming Integrity entry match in amount and occur one second apart.

Group Transaction Receipts and Payments Records csv
The same ledger shows Wuyi receiving payments directly from PLA and public-security organizations. The invoice material provides a clean customer-payment chain. Wuyi issued an invoice to the Beijing Applied Science and Technology Research Institute on 20 December 2024 for RMB 1.145 million in technical services.
A separate verification record confirms the invoice details. Six days later, the financial ledger records a payment from the institute into the Wuyi account for exactly RMB 1.145 million. Personnel carried under Wuyi also appear inside Integrity technical organizations, including Network Data Intelligence R&D, DPOC, the AR Laboratory, and cyber-range functions.
Public corporate filings already identify Wuyi as an Integrity subsidiary. The leak shows how closely the personnel and financial structures overlap in practice. For collection purposes, searches limited to the parent company’s legal name will miss part of the picture.
The next useful documents are the ones that connect customers to technical work. The unexplained Unit 78021 payments are the clearest starting point. The known contract explains only part of the money received from the unit. Contracts, invoices, acceptance reports, or technical annexes tied to the remaining payments could reveal additional projects.

The same approach should be applied to other repeat PLA counterparties, especially Units 32087, 32047, 61770, and 32057. Internally, priority should go to A0x34, K0x33, DPOC, Network Data Intelligence R&D, and Chunqiu Yundun R&D Center. Project records tied to those units may clarify what Integrity meant by “special industry” and which customers received their work.
Cyber-range scenario files would be particularly valuable. Target templates, scoring records, red-team tasking, exercise plans, or industrial-control scenarios could show whether military customers used Integrity ranges for operator training or mission rehearsal. The APT platform presents a similar gap. Customer records, exports, actor profiles, or scenario packages would help determine whether threat intelligence was used only for analysis or also fed training and exercise development.
The reconnaissance corpus needs sector-level review rather than isolated interpretation. Repeated collection against Taiwan government, defense, telecom, research, or civil-society targets would carry more weight than any single crawl file.
The uploaded records show Integrity operating across offensive security and threat intelligence. They also show work in cyber ranges and industrial simulation. Other records document military procurement and critical-infrastructure defense. The Unit 78021 material provides the strongest financial corroboration. The attack-team report offers the clearest evidence of hands-on offensive skill. The National Energy Group contract shows the depth of the company’s IT/OT simulation capability. The Three Gorges material establishes direct work inside a major energy-defense environment.
These findings place Integrity in a position to support PRC cyber force development through commercial expertise and infrastructure. The main gap is operational. The current files do not show a PLA tasking chain linking Integrity personnel to ranges or intelligence systems used in a foreign intrusion. Establishing that link or determining that it did not exist remains the central collection requirement.