Integrity Technology Group sold itself as a Beijing cybersecurity company. The Justice Department and the FBI described a different product: the infrastructure behind Flax Typhoon, a Chinese state-sponsored hacking cluster, and a botnet of hijacked cameras, routers, and storage boxes that let those operators look like ordinary internet traffic. On September 18, 2024, the Justice Department unsealed a court-authorized disruption in the Western District of Pennsylvania that pried malware off victim devices. On January 3, 2025, the Treasury Department’s Office of Foreign Assets Control put the company on the sanctions list. On March 16, 2026, the Council of the European Union listed the same firm for cyberattacks against member states. Two governments, three tools, one letterhead.
Treasury’s January notice said Flax Typhoon has been active since at least 2021 and has often targeted U.S. critical infrastructure. Between summer 2022 and fall 2023, the department said, Flax Typhoon actors used infrastructure tied to Integrity Tech while breaking into victim networks, and they routinely sent and received information through it. One intrusion Treasury cited was a California organization in the summer of 2023, where multiple servers and workstations were compromised. The legal hook was Executive Order 13694, as amended by Executive Order 13757, the cyber-sanctions authority aimed at significant malicious cyber-enabled activity that threatens U.S. national security, foreign policy, or economic stability.

The FBI’s account, laid out in the botnet case and in Director Christopher Wray’s remarks the same week at the Aspen Cyber Summit, was more specific than a logo. Hackers working for Integrity Technology Group, tracked in the private sector as Flax Typhoon, had infected consumer gear — small-office routers, IP cameras, digital video recorders, and network storage — and tied those machines into a network the company controlled. The Justice Department said the botnet covered more than 200,000 devices in the United States and abroad. Researchers at Black Lotus Labs described a related network they called Raptor Train, with a June 2023 peak above 60,000 devices. The counts measure different slices. Both describe a business that turned other people’s appliances into cover.

品牌控制面板
Court papers said Integrity Technology Group, a publicly traded company headquartered in Beijing, built an online application so customers could log in and run commands on chosen infected devices. The menu of those commands was labeled a “vulnerability-arsenal.” The application carried the brand KRLab, one of the company’s public names. Investigators said the company also used China Unicom Beijing Province Network internet addresses to manage the botnet. Wray told the Aspen audience that the group “represent themselves as an information security company, the Integrity Technology Group,” and that its chairman had publicly admitted collecting intelligence and performing reconnaissance for Chinese government security agencies. He said Flax Typhoon had been “targeting critical infrastructure across the U.S. and overseas, everyone from corporations and media organizations to universities and government agencies.”
About half the devices, Wray said, were in the United States. The Bureau, with a court order, sent commands that removed the malware, which he described as prying the machines “from China’s grip.” The operators tried to interfere with that disruption. They did not stop it. A takedown is not a retirement. It is a lost network. When the FBI announced another China-linked botnet disruption on August 26, 2026, against a group tracked as QTFY, Cyber Division officials described the Flax Typhoon operation as one entry in a series that also included Volt Typhoon. The letterhead changes. The contractor model does not.
列入制裁清单的实际削减情况
OFAC’s designation blocks Integrity Tech property and interests in property that are in the United States or in the possession or control of U.S. persons, and it bars Americans from dealing in them. Entities owned 50 percent or more by a blocked person are blocked as well. Banks and cloud companies that want to stay inside the dollar system have to treat the name as closed. That is not a criminal conviction. Integrity Tech called the U.S. action factually baseless in public comments after the listing, which is what a firm says when it still wants customers. Treasury does not litigate press releases. It publishes a name.
The January 3 package did not name individual engineers or executives. A company-only listing is easier to route around with a fresh letterhead than a package that also grounds the people who write the code. The European listing, Council Implementing Regulation (EU) 2026/589 of March 16, 2026, went after the company under the EU’s cyber sanctions regime. Brussels identified Integrity Technology Group, also rendered in Chinese as 永信至诚科技集团股份有限公司, registered on September 2, 2010, with unified social credit code 91110108562135265P. The Council said the company facilitated attacks linked to Flax Typhoon and that, between 2022 and 2023, the group used Integrity products and technology to access at least 65,600 internet-of-things devices in six member states. The same decision froze assets and barred EU persons from making funds available. China’s foreign ministry said the next day that it opposed the measures and told Brussels to correct what it called an erroneous approach, Reuters reported.
The EU vote was not a Flax Typhoon-only day. The same package listed the Chinese firm Anxun Information Technology, also known as i-Soon, and two of its co-founders, plus the Iranian company Emennet Pasargad. Politico reported that the United Kingdom had already sanctioned Integrity Technology Group and Anxun before Brussels acted. The pattern is a contractor market: a private company, a state customer, and a product line that looks like security until a warrant describes the control panel.
不要将此锁定为国库本身的漏洞
Four days before the OFAC notice, on December 30, 2024, Treasury told Congress that Chinese state-sponsored hackers had reached department workstations and taken unclassified documents through a compromised BeyondTrust remote-support key. That intrusion and the Flax Typhoon listing are not the same operation. Mixing them is how a news cycle invents a single master key that does not exist. Leaving them in separate silos is also a mistake. Read them together as a procurement problem. One hallway was an American remote-access vendor. The other was a Chinese company accused of renting pipes and infected appliances to a state cluster. The department was the victim on Monday and the accuser on Friday. The 财务处工作站的可信妥协 是第一个文件。 此名为第二.
Sanctions cannot patch a camera in a hallway. They cannot compel a Chinese courtroom to produce an engineer. They cannot rewind the California intrusion from the summer of 2023. They can tell every correspondent bank that this particular Beijing letterhead is done inside the dollar system, and they can tell every European company the same thing inside the EU’s asset-freeze rules. That is a modest tool. It is also one of the few a finance ministry has when the alternative is an indictment that will never see a defendant.
U.S. firms that still have Integrity Tech in a vendor spreadsheet now have a compliance problem, not a debate about attribution style. The 50 percent rule does not care about a rebrand. The AEGIS Alliance will treat the listing as an open file for as long as incident reports still find this company’s infrastructure in someone else’s network. Adjacent reading is in 黑客新闻,包括后来 声称运营商从一台中国超级计算机上偷走了10个微字节 编辑 Google 将一个使用手机作为静悄悄的互联网出口的影子网络摧毁3个制裁名单上的一家安保公司不是结案。 这是关于谁有钱看门的警告。









