#flaxTyphoon
@ncsc.gov.uk
Integrity Tech-enabled actors use AI, botnets and exploitation to steal sensitive data globally.
-
IOCs: Flax Typhoon
-
#China #FlaxTyphoon #ThreatIntel
China-Linked Actors Target Global Data
www.ncsc.gov.uk
October 8, 2026 at 8:11 PM
October 8, 2026 at 9:01 PM
CISA orders patch by Oct 11 after Flax Typhoon exploited five new vulnerabilities across ProFTPD, Struts, Strapi. #Cybersecurity #FlaxTyphoon #CISA #Vulnerabilities #ThreatIntel https://thedailytechfeed.com/china-linked-flax-typhoon-hits-5-new-vulnerabilities-cisa-orders-patch-by-oct-11/
October 9, 2026 at 1:05 PM
FBI has seized domains linked to #FlaxTyphoon, a China-linked hacking group accused of targeting US critical infrastructure. The operation has disrupted tools like “Microscan” and “FishHub, used for scanning and phishing.

Read: hackread.com/fbi-seizes-f...

#Cybersecurity #Phishing #China
FBI Seizes Flax Typhoon Hacking Tools Linked to Chinese Contractor
The FBI and DOJ seized domains and disrupted scanning and spear-phishing tools used by Flax Typhoon, a China-linked threat group tied to Integrity Technology Group.
hackread.com
October 8, 2026 at 11:23 PM
The FBI and DOJ seized seven online addresses and disrupted platforms used by Flax Typhoon.

Authorities say they supported tar…

https://en.hacks.gr/oi-ipa-kateschesan-epta-dieythynseis-kai-mplokaran-platformes-poy-chrisimopoioyse-i-flax-typhoon/

#FlaxTyphoon #EtherealPanda #CriticalInfrastructure
October 9, 2026 at 7:04 AM
CISA added five software flaws to its known-exploited list after their use by China-linked Flax Typhoon.

The wider operations targeted eight flaws to gain a…

https://en.hacks.gr/i-cisa-prosthetei-pente-provlimata-asfaleias-poy-chrisimopoiithikan-se-epitheseis/

#FlaxTyphoon #ProFTPD #SensitiveData
October 9, 2026 at 1:39 PM
The FBI and DOJ seized seven online addresses with court approval, linked to tools authorities say supported targeted deceptive message…

https://en.hacks.gr/oi-amerikanikes-arches-kateschesan-7-dieythynseis-poy-syndeontai-me-ergaleia-epitheseon-kai-klopis-archeion/

#Microscan #FishHub #FlaxTyphoon
October 9, 2026 at 2:35 AM
🚨 A suspected Chinese state-backed hacking group, likely Flax Typhoon, remained hidden in a target’s network for over a year by turning a component of Esri’s ArcGIS mapping tool into a stealthy web shell.
#CyberSecurity #ThreatIntel #APT #China #FlaxTyphoon
October 14, 2025 at 12:59 PM
XI Jinping and FlaxTyphoon both need a hobby.
September 19, 2024 at 5:06 PM
‼️ The router on the shelf is now a national-security problem 📰 Read the complete article from ComplexDiscovery OÜ's cybersecurity beat at complexdiscovery.com/the-router-o.... #Cybersecurity #CyberThreats #VoltTyphoon #FlaxTyphoon #CISA #FBI #NCSC #Botnet
April 24, 2026 at 5:45 PM
Chinese gang used ArcGIS as a backdoor for a year – and no one noticed
www.theregister.com/2025/10/14/c...

#FlaxTyphoon turned trusted mapping software into a covert backdoor.
#CyberSecurity #InfoSec #CyberEspionage
Chinese gang used ArcGIS as a backdoor for a year
: Crims turned trusted mapping software into a hideout - no traditional malware required
www.theregister.com
October 16, 2025 at 9:11 AM
"Researchers warn of a new IoT botnet called #RaptorTrain that already compromised over 200,000 devices worldwide." securityaffairs.com/168563/malwa... "experts believe the botnet is controlled by a #China -linked APT group #FlaxTyphoon (also called Ethereal Panda or RedJuliett)" #cybersec #natsec
Experts warn of China-linked APT's Raptor Train IoT Botnet
Researchers warn of a new IoT botnet called Raptor Train that already compromised over 200,000 devices worldwide.
securityaffairs.com
March 5, 2025 at 6:21 PM
We explored if #FlaxTyphoon activity was detectable within AIDE.

Our analysis revealed tactics including VPN tunneling, web shell traffic, and credential-based reconnaissance.

Read more in Meghal Donde's insightful and data-packed post: globalcyberalliance.org/flax-typhoon...
Catching Flax Typhoon in the Honeypot: Footprints in AIDE - GCA | Global Cyber Alliance | Working to Eradicate Cyber Risk
Our analysis revealed behavioral signals and infrastructure overlaps consistent with Flax Typhoon’s tactics.
globalcyberalliance.org
May 12, 2025 at 12:29 PM
China-linked hackers now exploit compromised SOHO routers and IoT devices to build covert botnets for cyber espionage, says NCSC. Agencies recommend monitoring edge-device traffic and VPN access closely. #China #Botnets #IoTsecurity
Compromised everyday devices power Chinese cyber espionage operations - Help Net Security
China-linked threat actors have shifted from individually procured infrastructure to large-scale covert networks and botnets built from compromised SOHO routers, IoT, and other edge devices, the NCSC warns. The NCSC and partner agencies issued an advisory urging organizations to map and baseline edge-device traffic, monitor VPN and remote access connections, and adopt dynamic threat-feed filtering using known covert-network indicators. #FlaxTyphoon #IntegrityTechnologyGroup
www.hendryadrian.com
April 25, 2026 at 4:45 AM
#Botnetz unter Kontrolle des chinesischen Staates vom FBI übernommen

Die Gruppe #FlaxTyphoon, zielte auf kritische Infrastrukturen in den USA und anderen Ländern ab. Betroffen waren Unternehmen, Medienorganisationen, Universitäten und Regierungsbehörden

winfuture.de/news,145385....
Botnetz unter Kontrolle des chinesischen Staates vom FBI übernommen
Die US-Bundespolizei FBI hat ein Botnetz, bestehend aus hundert­tau­sen­den internetfähigen Geräten wie Kameras, Videorekordern, Spei­cher­geräten und Routern, unter Kontrolle gebracht. Dieses wurde v...
winfuture.de
September 19, 2024 at 8:26 AM
📰 Inggris Peringatkan Peretas Tiongkok Gunakan Jaringan Proksi untuk Hindari Deteksi

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/04/23/inggris-peringatkan-peretas-tiongkok-gunakan-jaringan-proksi-botnet-untuk-hindari-deteksi/

#ber
it#beritaTeknologie#botnetT#flaxTyphoonn#jaringanProk
April 23, 2026 at 1:45 PM
👥 Beijing Cybersecurity Company Caught in the US OFAC Radar. Read full story ⤵️

#Cybercrime #CyberEspionage #FlaxTyphoon #USTreasury #Sanctions #StateSponsored #China #ThreatActors
US Sanctions Beijing Based Cybersecurity Company
A Chinese company was sanctioned for cyberespionage on the United States government and related infrastructure via a cybercriminal group.
www.technadu.com
January 6, 2025 at 5:57 AM
Geospatial Tool Turned Into Stealthy Backdoor by Flax Typhoon #ArcGIS #BackdoorAttacks #FlaxTyphoon
Geospatial Tool Turned Into Stealthy Backdoor by Flax Typhoon
 Chinese state-backed hacking group Flax Typhoon has been exploiting a feature within Esri’s ArcGIS software to maintain covert access to targeted systems for more than a year, according to new findings from ReliaQuest. The group, active since at least 2021 and known for espionage operations against entities in the U.S., Europe, and Taiwan, weaponized ArcGIS’s Server Object Extension (SOE) to transform the software into a webshell—essentially turning legitimate features into tools for persistent compromise. Researchers found that the attackers targeted a public-facing ArcGIS server linked to a private backend server. By compromising the portal administrator credentials, they deployed a malicious extension that forced the system to create a hidden directory, which became their private command and control workspace.  This extension included a hardcoded key, shielding their access from others while ensuring persistence. The hackers maintained this access long enough for the malicious file to become embedded in backup systems, effectively guaranteeing reinfection even if administrators restored the system from backups. ReliaQuest described this as a particularly deceptive attack chain that allowed the group to mimic normal network activity, thereby bypassing typical detection mechanisms. Because the infected component was integrated into backup files, standard recovery protocols became a liability — a compromised backup meant a built-in reinfection vector. The tactic showcases Flax Typhoon’s hallmark strategy of exploiting trusted internal processes and tools rather than relying on advanced malware or sophisticated exploits. This method is consistent with Flax Typhoon’s history of leveraging legitimate software components for espionage. Microsoft had previously documented the group’s capability to maintain long-term access to dozens of Taiwanese organizations using built-in Windows utilities and benign applications for stealth. The U.S. Treasury Department has sanctioned Integrity Technology Group, a Beijing-based company implicated in supporting Flax Typhoon’s operations, including managing infrastructure for a major botnet dismantled by the FBI. ReliaQuest warned that the real danger extends beyond ArcGIS or Esri’s ecosystem — it highlights the inherent risks in enterprise software that depends on third-party extensions or backend access. The researchers called the case a “wake-up call,” urging organizations to treat every interface with backend connectivity as a high-risk access point, regardless of how routine or trusted it appears.
dlvr.it
October 22, 2025 at 2:06 PM
Chinese state-sponsored hackers exploited ArcGIS servers for over a year, turning them into backdoors for cyber espionage. #CyberSecurity #FlaxTyphoon #ArcGIS #CyberEspionage Link: thedailytechfeed.com/chinese-stat...
October 15, 2025 at 7:12 AM
Flax Typhoon trasforma una SOE ArcGIS in web shell persistente e usa SoftEther VPN per spionaggio e credential harvesting in attacco di lunga durata.

#apt #ArcGIS #cina #credentialharvesting #FlaxTyphoon #SOE #VPN #webshell
www.matricedigitale.it/2025/10/14/f...
October 14, 2025 at 3:10 PM