Alleged Integrity Technology Group Data Leak: A Botnet, and a Purchase Order
In August 2026, a threat actor advertised a dataset said to have been stolen from Integrity Technology Group, a Beijing security vendor sanctioned by the United States and the European Union, and four days later said it had sold. KELA's Cyber Intelligence Center reviewed the sample files the seller released: a network surveillance system white paper, a bulk order of static residential proxy IPs and cloud phones, and a payment agreement naming a PLA unit. The sanctions record describes infrastructure the company compromised; these documents describe infrastructure it bought.
Published September 8, 2026

Executive Summary
In August 2026, a threat actor operating under the moniker "CodingFarmer996" advertised what they claimed to be a massive confidential dataset stolen from Integrity Technology Group Inc.(永信至诚科技集团股份有限公司) on a cybercrime forum. Integrity Technology Group, a high-profile Chinese cybersecurity vendor and state-designated "Little Giant" enterprise, has been sanctioned by both the United States and the European Union over its role in state-linked cyber operations. Western governments place the company at the intersection of private commerce, state espionage, and military cyber-operations.
If the leaked materials are authentic, they provide significant technical evidence supporting the suspected links to the state-led activities. KELA’s analysis of the provided sample documents suggests the company’s potential involvement in developing national-grade traffic decryption systems, procuring static residential proxy IP infrastructure of the kind used by Chinese APTs to obscure the origin of network activity, and maintaining lists of regional network nodes across East Asian democratic territories.
Background: About Integrity Technology Group
Headquartered in Beijing, Integrity Technology Group is recognized inside China as a prominent provider of cyber range (网络靶场) platforms, security evaluations, and defensive training services. However, Western authorities take a different view of the firm's capabilities. The United States sanctioned the company in January 2025 and the European Union followed in March 2026.
U.S. Sanctions (January 3, 2025): The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated Integrity Technology Group over its role in computer intrusions against U.S. victims. Treasury states that between summer 2022 and fall 2023, Flax Typhoon, which it describes as a state-sponsored Chinese group active since at least 2021, routinely exchanged data with infrastructure tied to the company.
EU Sanctions (March 16, 2026): The Council of the European Union imposed restrictive measures on the company, finding that it provided technical and material support for cyber-attacks with a significant effect. The listing records that between 2022 and 2023, Flax Typhoon reached at least 65,600 internet-connected devices across six EU member states by using the company's products.
Both actions rest on the same underlying conduct. The joint advisory published by the FBI, NSA, and Cyber National Mission Force in September 2024, which Treasury cites in its designation, states that Integrity Technology Group controlled and managed a botnet, comprising more than 260,000 devices as of June 2024, with compromised systems observed across North America, South America, Europe, Africa, Southeast Asia, and Australia. The EU acted in the same instrument that listed Anxun Information Technology, better known as i-Soon, placing the company inside a wider pattern of Chinese commercial security contractors sanctioned for state-linked work.
Forum Threads & Leaked Archive Overview
On August 22, 2026, CodingFarmer996 posted a thread in DarkForums and Pwnforums. The seller claimed to offer a comprehensive archive belonging to Integrity Technology Group, which they asserted includes:
Corporate & Financial Records:
Internal cash flow details (for example August 2025 fundraising records), bank details, and identification documents belonging to board members.
Exfiltrated Target Data:
Profile pictures, private emails, digital certificates (.cer), and certificate signing requests (.csr) harvested from organizations in Taiwan, Vietnam, and Hong Kong.
Technical White Papers:
Documents introducing the "Network-Sensitive Data Surveillance System" and the "Website Backend Administrator Discovery System".
Credential Listings:
A spreadsheet containing credentials for domestic and foreign cloud platforms (including Alibaba Cloud, OgCloud, Tencent Cloud, and AdsPower browser profiles).
Procurement and Technology Contracts:
Agreements involving various domestic security units, academic institutions, and administrative contractors.
On August 26, 2026, the seller made a follow-up post stating that the data had been sold.
Forum thread posted by "CodingFarmer996" advertising the alleged leak of Integrity Technology Group
KELA’s analysis confirms the CodingFarmer996 account was created in August 2026 on both forums, with no other confirmed activity aside from the post regarding this data leak and a few comments left across several threads. Notably, the phrase 'Contact for price。' was punctuated with a double-byte East Asian ideographic full stop (。), commonly used in Chinese and Japanese input methods (IMEs). Given the actor's moniker 'CodingFarmer996’, a nod to the notorious Chinese tech-industry work schedule, this punctuation suggests the use of an active Chinese language input system during the creation of the post.
Key Observations from Sample Analysis
The threat actor's forum post provided sample links containing seven PDF documents and five image files, including what appear to be internal documents related to Integrity Technology Group spanning from 2015 to 2025. Our analysis of the leaked samples highlights three key claims that, if verified, would shed light on the company's suspected support for offensive cyber operations.
1. Development of Interception and Traffic Decryption Systems for Surveillance
The seven PDF files appear to be documents showing ties to state-led cyber operations, including technological foundations for surveillance and cryptanalysis. Among the files is a white paper detailing a system named the Network-Sensitive Data Surveillance System (网络敏感数据侦控系统).
Cover page of Integrity Technology Group's product white paper for the "Network-Sensitive Data Surveillance System"
KELA found out from the document that the system is designed to be deployed at network egress points to intercept and decrypt traffic traveling through "hidden channels" (隐蔽通道), specifically targeting circumvention tools such as Freegate, Shadowsocks, and TigerVPN.
Technical specifications highlighting target circumvention tools
KELA also identified details in the white paper stating that the system can bypass encryption to extract physical hardware fingerprints, including MAC addresses, hostnames, OS types, and mobile IMEI/IMSI codes, and reconstruct plain-text messages and forum posts. It also describes several case studies where local Public Security Bureaus reportedly deployed this technology to locate the physical origins of encrypted traffic and identify key targets of interest.
System administration console displaying decrypted text and captured hardware metadata
2. Potential Provision of Covert Proxy/Botnet Infrastructure and Military Range Contracts
The five image files appear to be screenshots of documents believed to be related to infrastructure procurement and account management for state-led cyber activities. Several images appear to outline the logistical support structures that could be utilized to build or maintain covert routing networks.
Suspected PLA Unit Contract:
The samples include a tripartite payment agreement involving PLA Unit 61770, Integrity Technology Group, and its wholly-owned subsidiary, Beijing Yongxin Huoyan Technology Co., Ltd.(北京永信火眼科技有限公司). This agreement relates to a "network range platform" (网络靶场平台) project originally contracted in November 2021 at 5,895,000 RMB, revised to 5,543,300 RMB after a military price review, with 277,220.50 RMB outstanding at the time of signing.
Signed tripartite payment agreement involving PLA Unit 61770 and Integrity Technology Group
The "JW Resource Service" Acceptance Report:
KELA observed a 2023 document titled "JW Resource Service Project Acceptance Request Report," which bears the name of Beijing Wuyi Jiayu Technology Co., Ltd.(北京五一嘉峪科技有限公司), a wholly-owned subsidiary of Integrity Technology Group. It details the delivery of 55 cloud servers, 100 cloud node servers, 2,700 cloud mobile phones, 7,000 static residential proxy IPs, 28 multi-profile browser accounts, and 6,500 Facebook accounts alongside a quantity of Twitter/X accounts, configured with the AdsPower anti-detect browser, against a contract signed on October 18, 2023 and running to October 19, 2024.
If genuine, such resources would provide an ideal environment for establishing the resilient, hard-to-track proxy networks often associated with stealthy cyber operations like those of Flax Typhoon.
Cover page of the "JW Resource Service" infrastructure project acceptance report
3. Deep-Dive Analysis of the Listed East Asian IP Address Clusters
Another image shows a directory listing exactly 10 specific IP addresses each for Japan, Hong Kong, and Taiwan, totaling 30 IPv4 node
Exfiltrated East Asian network nodes (labeled "Japan, Hong Kong, Taiwan")
Per KELA’s technical analysis, these IP lists are not organic or randomly assigned user endpoints, but rather represent highly coordinated, professionally managed network nodes. Key characteristics of these IP clusters include:
Regional B-Class Uniformity:
The 10 IP addresses within each region share identical upper 16-bit blocks (Japan: 163.5.x.x, Hong Kong: 174.136.x.x, Taiwan: 149.88.x.x), indicating systematic regional categorization.
High Subnet Concentration:
Rather than being scattered, the addresses are heavily concentrated into a very narrow set of /24 subnets. For instance, the Japanese IPs are limited to just two subnets (.72 and .77), while the Hong Kong and Taiwanese addresses are restricted to only three subnets each.
Datacenter and Cloud Hosting Infrastructure:
The identified network segments are hosted on datacenter infrastructure leased from Bunny Communications (AS5065) and Wisdom Cloud Internet Technology (AS197537), rather than major internet service providers (ISPs).
Likely Proxy, VPN, or Scraping Infrastructure:
Given that these subnets were acquired in bulk from the same hosting providers, it is highly probable that they are operated as cross-regional proxy server pools, VPN nodes, or automated scraping infrastructures rather than standard user systems.
The highly structured and centralized nature of these IP nodes suggests that the exfiltrated list does not track organic user traffic, but rather represents a deliberate inventory of data center-based proxy network nodes or operational relay stations used in coordinated activities across East Asia.
KELA Cyber Intelligence Center Perspective
Our researchers have provided the following key findings and conclusions that can be inferred or supported:
Threat Actor Origin:
Per KELA's review, the threat actor "CodingFarmer996" operated a newly created account and used Chinese IT terminology alongside East Asian double-byte punctuation (。), indicating that the data leak listing was authored by an active Chinese-language user.
Mechanics of Surveillance and Anti-Circumvention:
Rather than demonstrating basic censorship blocking, the white paper findings shed light on the operational details of state surveillance, tracking, and law enforcement targeted at citizens attempting to bypass censorship. According to the leaked document, the system is engineered to intercept hidden channels and decrypt circumvention tools like Freegate and Shadowsocks. Furthermore, KELA also identified details stating the software bypasses encryption to extract physical hardware fingerprints (such as MAC addresses and IMEI codes) and reconstruct plain-text messages, which local Public Security Bureaus reportedly deployed to physically trace and identify targets.
APT Infrastructure Provisioning:
The procurement logs and IP cluster analysis provide supporting data regarding the firm's role in state-sponsored cyber operations, offering a fresh perspective separate from existing public record claims. Western sanctions primarily cited Integrity Technology Group for managing botnets composed of hijacked, compromised third-party devices. In contrast, KELA observed a 2023 "JW Resource Service" report detailing bulk orders of static residential proxy IPs and cloud phones, while technical analysis indicated that the exfiltrated East Asian IP addresses represent professionally managed datacenter nodes. This may suggest the firm did not solely rely on hijacked devices, but actively procured and maintained legitimate stealth routing infrastructure aligned with the operational tactics of APT groups like Flax Typhoon.
In the absence of corroborating evidence, the claims should be treated with caution. Nevertheless, several elements of the leaked samples appear credible, including operational details and provisioning logs that align with infrastructure-building tactics attributed to Flax Typhoon and referenced in Western sanctions.
The samples do not corroborate the sanctioned conduct itself: the US and EU actions concern a botnet assembled from compromised third-party devices, while the resources itemized here, leased servers, cloud phones, purchased proxy addresses, and social media accounts, were bought rather than compromised. Read together, they suggest two parallel capabilities rather than one, and the procured inventory is the side the public record has said least about.
If authentic, the materials provide further insight into the potential role of private-sector entities in supporting Chinese state-sponsored cyber operations.
Recommendations
The documents in this sample set span 2015 to 2025, and the most recent contract among them ran out in October 2024. Nothing here describes a live intrusion, so the value of the material is retrospective and structural rather than operational. Five things follow from it.
Hunt the listed ranges, make your own assessment.
The 30 addresses fall into three narrow groups of adjacent /24 subnets, each inside a single /16 block, and each hosted on leased datacenter space rather than consumer ISP allocations. Search historical logs and netflow for connections to and from those blocks across the period the documents cover.
ACTION:
In KELA CONTROL, an address or domain can be added to a case as a seed asset and analyzed against netflow records, which surfaces the addresses observed communicating with it and adds them to the case automatically; adding one of your own edge assets alongside the seed lets you highlight the path between the two and see what infrastructure sits in between. Where a node has a distinctive TLS or certificate fingerprint, the same module will look for other addresses sharing it, which is how the rest of a relay pool tends to surface.
Blocking the ranges isn’t advised unless you have done your own assessment as the provenance of the list is unverified, the function of each node is undocumented, and shared hosting ranges carry unrelated tenants who would absorb the collateral. Read the regional labels as a statement about where the nodes sit, not as a list of who was targeted. The document groups the addresses by geography and says nothing at all about victims.
ACTION:
Run the ranges against criminal sources as well as your own logs. KELA Investigate takes an IP range in CIDR notation and returns anything in the cybercrime data lake containing an address inside it, with several ranges combinable in one query, and that query can be saved with a daily or weekly email policy so that a later mention of the same infrastructure reaches you without anyone remembering to look.
Stop treating residential address space and in-region geolocation as trust signals.
The acceptance report itemizes 7,000 static residential proxy IPs, 2,700 cloud phones, and 100 cloud node servers delivered under a single service contract. Any control that infers legitimacy from a residential ASN, a domestic IP range, or a plausible in-country device fingerprint is defeated by a purchase order rather than by a technique.
ACTION:
Review where those signals still carry weight in fraud scoring, conditional access, geofencing, and bot detection, and treat a residential origin as neutral rather than reassuring.
- Screen the whole corporate structure, not just the listed name.
The samples name two wholly-owned subsidiaries, and one of them appears as the receiving party on a military contract signed by the parent, with payment routed through the subsidiary rather than to the sanctioned entity itself. Sanctions and vendor screening keyed to a listed name alone will not see an arrangement of that shape.
ACTION:
Extend screening to ownership structure and to the counterparties named on the paperwork, and revisit third-party inventories where a supplier's ultimate ownership was never mapped.
Separate procured infrastructure from compromised infrastructure in your detection thinking.
The sanctions record against this company concerns a botnet assembled from compromised third-party devices, and detection guidance has followed accordingly. What these documents itemize is bought: leased servers, purchased proxy addresses, rented cloud phones, and social media accounts supplied as inventory. Procured infrastructure produces different telemetry, sits in different address space, and answers to different takedown routes than a botnet does. A programme tuned only to the compromised variety will not see the other.
ACTION:
When you classify infrastructure inside a tool, make the distinction explicit in the rules rather than leaving it to judgment. When using KELA CONTROL, for example, classification on ASN, organization, geolocation, open ports, and asset infrastructure type is automated and immediately available, which is enough to separate bulk-leased hosting from consumer endpoint space at the point assets enter a case.
Test the seller before you test the data.
The account that listed this archive was created the same month it sold and has no other confirmed trading history, which is the single most important fact about the offer and the easiest one to skip past. A persona with no history is not evidence of fraud, but it removes the usual basis for believing a claim, so the burden shifts entirely onto the samples.
ACTION:
Where a handle does have a past, that past is checkable. KELA Threat Actors profiles carry the handles a persona has used across platforms with the date of each change, the date they joined each source, and a posting timeline showing first and last activity, each value referenced back to the source that informed it. Doing that check first tells you whether you are looking at an established vendor, a rebrand, or someone who appeared in time to sell one thing.
Conclusion
The takeaway is that the most durable finding here is not any single document but the shape of the arrangement as a whole: capability assembled through ordinary commercial procurement, invoiced and signed for, operating alongside the compromised infrastructure that public reporting has already covered in detail.
Integrity Technology Group FAQ
What is Integrity Technology Group?
Integrity Technology Group is a Beijing-headquartered Chinese cybersecurity company known domestically for cyber range platforms, security evaluations, and defensive training. It was sanctioned by the United States in January 2025 and by the European Union in March 2026, in both cases over its assessed role in supporting state-linked cyber operations.
Has the Integrity Technology Group data leak been confirmed?
No. A seller advertised the dataset on two cybercrime forums in August 2026 and posted four days later that it had sold, but neither the company nor any government has confirmed a breach, and the dataset itself has not been independently authenticated. In summary, the sample files are internally consistent and consistent with the public record, and consistency is not authentication.
What did the sample files contain?
The seller published seven PDF documents and five images. They include a product white paper for a network traffic interception and decryption system, a three-party payment agreement naming a People's Liberation Army unit and two company subsidiaries, an acceptance report for a bulk order of cloud servers, cloud phones, static residential proxy IPs, and social media accounts, and a table of 30 IP addresses grouped under Japan, Hong Kong, and Taiwan.











