Flax Typhoon is a Chinese state-sponsored cyber espionage group targeting organizations in Taiwan.
Analyst brief
Flax Typhoon is a Chinese state-sponsored cyber espionage actor. It primarily targets organizations in Taiwan, focusing on achieving long-term persistence with minimal malware footprint. Key TTPs include exploiting vulnerabilities in public-facing servers, using living-off-the-land techniques through built-in OS tools, and deploying VPN connections for lateral movement. Defenders should monitor for anomalies like unusual PowerShell or WMI activity, unauthorized VPN connections, and prioritize patching public-facing servers.
Flax Typhoon
Ethereal PandaStorm-0919
unknown
Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan. They conduct espionage campaigns and focus on gaining and maintaining long-term access to networks using minimal malware. Flax Typhoon relies on tools built into the operating system and legitimate software to remain undetected. They exploit vulnerabilities in public-facing servers, use living-off-the-land techniques, and deploy a VPN connection to maintain persistence and move laterally within compromised networks.