Flax Typhoon
Flax Typhoon is a China-linked, PRC state-sponsored threat actor also tracked as Ethereal Panda and Storm-0919. Microsoft described the group as China-based nation-state actors active since 2021, and U.S. officials said the group operated at the direction of the Chinese government. The private sector and U.S. government reporting in the provided content links Flax Typhoon to Beijing-based Integrity Technology Group, which the FBI assessed was responsible for intrusion activity attributed to the group and for developing and controlling the Raptor Train botnet. The group has targeted government agencies, education, critical manufacturing, and information technology organizations in Taiwan, as well as U.S. and foreign corporations, universities, government agencies, telecommunications providers, media organizations, and critical infrastructure. Multiple sources in the content state that Flax Typhoon targeted Taiwan and U.S. critical infrastructure, and Taiwan’s NSB named Flax Typhoon among Chinese groups involved in sustained targeting of sectors including energy, healthcare, communications, government, and technology. A defining element of Flax Typhoon activity in the provided reporting is the use of compromised consumer and edge devices as covert infrastructure. The group was linked to the Raptor Train botnet, which infected more than 200,000 and, in some reporting, more than 260,000 SOHO routers, IP cameras, DVRs, NVRs, NAS devices, modems, and similar IoT/network devices. The botnet was used to disguise malicious traffic as routine internet activity from victim devices and supported targeting of military, government, telecommunications, higher education, defense industrial base, and IT organizations, primarily in the United States and Taiwan. Reporting also states that Flax Typhoon-associated botnet activity included DDoS capability, DDoS attacks, and data theft, and that during the FBI disruption effort, China-based actors launched a DDoS attack against FBI infrastructure. The content also attributes hands-on intrusion tradecraft to Flax Typhoon. ReliaQuest attributed an ArcGIS Server compromise to the group, where the attackers used a malicious ArcGIS Server Object Extension, identified as JavaSimpleRESTSOE, to gain persistence and remote code execution through the ArcGIS Server management console. The persistence mechanism in that case involved a VPN executable named Bridge.exe created by the compromised ArcGIS REST SOE. Separate reporting noted overlap between base64-encoded whoami commands in another China-linked IIS intrusion cluster and a prior Flax Typhoon incident, suggesting shared tradecraft. Flax Typhoon has been reported using legitimate software for stealth and persistence. The content states that actors downloaded and used SoftEther VPN software to obfuscate activity, maintain persistence, and evade detection, including binaries masquerading as legitimate Windows processes such as conhost.exe and dllhost.exe. Additional reporting linked Flax Typhoon to protocol tunneling and abuse of external remote services. Known aliases in the provided content are Ethereal Panda and Storm-0919.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
Associated vulnerabilities
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
There was also widespread, global targeting, such as a government agency in Kazakhstan, along with more targeted scanning and likely exploitation attempts against vulnerable software including Atlassian Confluence servers and Ivanti Connect Secure appliances (likely via CVE-2024-21887) in the same sectors.
VulnCheck observed an attacker in the wild using mount as a “download and execute” GTFOBin while attempting to exploit Hikvision CVE-2021-36260... CVE-2021-36260 is a command injection vulnerability affecting the /SDK/webLanguage endpoint.
CISA first warned of the issues in September, when it ordered all agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA).
CISA first warned of the issues in September, when it ordered all agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA).
Observables
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Intrusion activity linked to a contractor-supported model in which Integrity Technology Group developed the Raptor Train botnet used to support operations.
China-linked threat actor referenced for similar base64-encoded command usage, suggesting overlap in tradecraft with OP-512.
China-linked threat actor targeting Taiwan and US critical infrastructure and leveraging compromised IoT devices to build botnets for offensive operations.
Linked in the content to use of CDN-based traffic concealment techniques and SoftEther VPN to maintain persistence and evade detection.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.