{"id":493,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2021<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">China (MSS)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage, Persistent Access<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Living-off-the-land techniques, VPN exploitation, Taiwan-focused espionage<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Ethereal Panda, RedJuliett<\/div>\n  <\/div>\n<\/div>\n<p>Flax Typhoon is a Chinese state-sponsored APT group attributed to the Ministry of State Security (MSS), primarily focused on cyber espionage operations targeting Taiwan and other entities of strategic interest to Beijing. The group was publicly exposed by Microsoft in August 2023, which assessed with high confidence that Flax Typhoon was operating on behalf of the Chinese government.<\/p>\n<p>A defining characteristic of Flax Typhoon's tradecraft is its heavy reliance on living-off-the-land (LotL) techniques ,  using built-in Windows operating system tools such as PowerShell, Windows Remote Management (WinRM), and legitimate remote administration software like legitimate VPN clients to maintain persistence and conduct lateral movement. This approach significantly reduces the group's malware footprint and makes detection by traditional signature-based security tools substantially more difficult.<\/p>\n<p>The group establishes initial access primarily by exploiting known vulnerabilities in public-facing servers and VPN appliances, before deploying China Chopper web shells and other minimal-footprint backdoors. Their primary targeting includes government agencies, educational institutions, critical manufacturing, and information technology organisations in Taiwan, with secondary targeting across Southeast Asia and other regions.<\/p>\n<p>In September 2024, the US Department of Justice announced the disruption of a Flax Typhoon-linked botnet comprising over 260,000 compromised IoT devices, which the group used to proxy their attack traffic and obscure their operational infrastructure ,  demonstrating the group's sophisticated and multi-layered approach to maintaining operational security.<\/p>\n\n<p><strong>Cyber Espionage Tactics and Persistence Mechanisms:<\/strong> Operational tracking indicates that <strong>Flax Typhoon<\/strong> executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.<\/p>","link":"https:\/\/cyberasia.io\/actor\/flax-typhoon\/","name":"Flax Typhoon","slug":"flax-typhoon","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}