Flax Typhoon is a China-based, Chinese state-sponsored cyberespionage threat actor also tracked as Ethereal Panda and Storm-0919. Associated activity has additionally been reported under the name Red Juliett. The group is linked to Integrity Technology Group, a Beijing-based cybersecurity contractor with Chinese government contracts that supplies tools, infrastructure, and network-compromise services to Chinese threat actors. Its targets include government agencies, universities, manufacturing and information technology organizations, critical infrastructure operators, and nongovernmental organizations. Documented targeting includes Taiwan, the United States, Japan, and Poland, with particularly extensive compromises of Taiwanese universities. Flax Typhoon combines automated reconnaissance with hands-on exploitation, spear phishing, credential harvesting, and password spraying against Microsoft Exchange and Microsoft 365. It relies heavily on living-off-the-land techniques and legitimate remote-access software to reduce detection and maintain access. SoftEther VPN installations provide persistent connectivity, including after system restarts, and may be disguised as legitimate operating-system components. Collection activities include database theft, Active Directory credential harvesting through DCSync, and email exfiltration from on-premises and cloud services. The group is associated with Raptor Train, a large botnet of compromised small-office/home-office and Internet-of-Things devices operated by Integrity Technology Group using a Mirai variant. Compromised devices support reconnaissance and conceal the origin of malicious traffic. Integrity Tech's MicroScan platform provides extensive vulnerability-scanning capabilities, while FishHub supports spear-phishing intrusions, follow-on malware delivery, unauthorized remote access, and targeted file theft. Approximately 20 Taiwanese universities were confirmed victims of FishHub-related activity. U.S. authorities disrupted the associated botnet in September 2024 and seized infrastructure supporting MicroScan, FishHub, and persistent VPN connections in October 2026.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
There was also widespread, global targeting, such as a government agency in Kazakhstan, along with more targeted scanning and likely exploitation attempts against vulnerable software including Atlassian Confluence servers and Ivanti Connect Secure appliances (likely via CVE-2024-21887) in the same sectors.
CVE-2014-6278 - GNU Bash operating system command injection vulnerability (aka Shellshock) (Added in October 2025)
CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
CVE-2015-5477 (CVSS score: 7.5) - A reachable assertion vulnerability in ISC BIND that could allow a remote attacker to cause a denial-of-service via TKEY queries.
CVE-2016-3081 (CVSS score: 8.1) - A command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
8 more CVEs tied to this actor tracked in Mallory.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese state-backed actor whose campaign allegedly exploited TP-Link routers among several router brands, according to congressional testimony cited in the complaints. The article notes that the written testimony provides no source for this claim. TP-Link disputed the testimony, saying the campaigns showed no discernible preference for TP-Link routers.
China-linked threat actor associated with operations enabled by China-based Integrity Technology Group. The reported operations exploit eight vulnerabilities to gain initial access to organizations, establish persistence through VPN software, and steal sensitive data, including emails and credentials.
A named hacking group linked by researchers to Integrity Technology Group, the company whose cyber-espionage infrastructure was disrupted. The article describes the company's operations but does not separately attribute particular tools, victims, or techniques to Flax Typhoon.
A Beijing-backed threat actor identified as having benefited from Integrity Technology Group's activities. The content does not specifically attribute the subsequently listed techniques or targeted sectors to Flax Typhoon.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.