🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
FLAX TYPHOON

/actor/flax-typhoon/  ·  0 intel reports

Year Established
2021
Attribution
China (MSS)
Motivation
Espionage, Persistent Access
Modus Operandi (MO)
Living-off-the-land techniques, VPN exploitation, Taiwan-focused espionage
Primary Aliases
Ethereal Panda, RedJuliett

Flax Typhoon is a Chinese state-sponsored APT group attributed to the Ministry of State Security (MSS), primarily focused on cyber espionage operations targeting Taiwan and other entities of strategic interest to Beijing. The group was publicly exposed by Microsoft in August 2023, which assessed with high confidence that Flax Typhoon was operating on behalf of the Chinese government.

A defining characteristic of Flax Typhoon's tradecraft is its heavy reliance on living-off-the-land (LotL) techniques , using built-in Windows operating system tools such as PowerShell, Windows Remote Management (WinRM), and legitimate remote administration software like legitimate VPN clients to maintain persistence and conduct lateral movement. This approach significantly reduces the group's malware footprint and makes detection by traditional signature-based security tools substantially more difficult.

The group establishes initial access primarily by exploiting known vulnerabilities in public-facing servers and VPN appliances, before deploying China Chopper web shells and other minimal-footprint backdoors. Their primary targeting includes government agencies, educational institutions, critical manufacturing, and information technology organisations in Taiwan, with secondary targeting across Southeast Asia and other regions.

In September 2024, the US Department of Justice announced the disruption of a Flax Typhoon-linked botnet comprising over 260,000 compromised IoT devices, which the group used to proxy their attack traffic and obscure their operational infrastructure , demonstrating the group's sophisticated and multi-layered approach to maintaining operational security.

Cyber Espionage Tactics and Persistence Mechanisms: Operational tracking indicates that Flax Typhoon executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles