Threat intelligence
- Suspected origin
- China
- First seen
- 2021-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Education, Government, IT, Manufacturing
- TLP
- WHITE
(Microsoft) Flax Typhoon has been active since mid-2021 and has targeted government agencies and education, critical manufacturing, and information technology organizations in Taiwan. Some victims have also been observed elsewhere in Southeast Asia, as well as in North America and Africa. Flax Typhoon focuses on persistence, lateral movement, and credential access. As with any observed nation-state actor activity, Microsoft has directly notified targeted or compromised customers, providing them with important information needed to secure their environments.
Flax Typhoon is known to use the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther virtual private network (VPN) client. However, Flax Typhoon primarily relies on living-off-the-land techniques and hands-on-keyboard activity. Flax Typhoon achieves initial access by exploiting known vulnerabilities in public-facing servers and deploying web shells like China Chopper. Following initial access, Flax Typhoon uses command-line tools to first establish persistent access over the remote desktop protocol, then deploy a VPN connection to actor-controlled network infrastructure, and finally collect credentials from compromised systems. Flax Typhoon further uses this VPN access to scan for vulnerabilities on targeted systems and organizations from the compromised systems.
Also known as
Ethereal PandaRedJuliett
Coverage 4
vulnerability
The U.S. CISA has added five vulnerabilities to its KEV catalog, which are being actively exploited by a China-linked threat actor (Flax Typhoon). These flaws include CVE-2015-3306, CVE-2021-3199, CVE-2023-22894, CVE-201…

apt
The United States has disrupted Chinese state-sponsored hacking tools – MicroScan (for vulnerability scanning) and FishHub (for network intrusion via spear phishing) – used by Integrity Tech. The US has seized associated…
vulnerability
The FBI has seized seven web domains linked to Chinese hacking tools operated by Integrity Technology Group, a firm linked to Beijing-backed cyber operatives. The FBI has disrupted a 260,000-device botnet associated with…

vulnerability
The FBI and six other agencies have issued an advisory detailing how Chinese-linked hackers, associated with Integrity Technology Group, are targeting organizations in Southeast Asia and beyond. These hackers use a sophi…
