Home/Threat Actor/Flax Typhoon
Threat Actor

Flax Typhoon

flax_typhoon · china · active since 2021

Flax Typhoon (Ethereal Panda / RedJuliett / Storm-0919 / UNC5007) is a Chinese state-sponsored cyber-espionage actor active since at least mid-2021, formally attributed to operations of Integrity Technology Group, a Beijing-based PRC commercial cybersecurity company sanctioned by US Treasury OFAC on January 3, 2025; established by the September 18, 2024 FBI/NSA/CNMF/Five Eyes joint cybersecurity advisory AA24-262A with the unsealed FBI affidavit stating Integrity Tech is 'responsible, at least in part, for the computer intrusion activities collectively attributed to Flax Typhoon', making this one of the most clearly attributed PRC-state-aligned clusters in the public corpus and paralleling the i-SOON-revealed MSS commercial-contractor model; distinguished by operation of the Raptor Train botnet (one of the largest state-aligned botnets ever publicly documented, grown from ~60,000 compromised devices in 2023 to over 260,000 by mid-2024 across SOHO routers, IP cameras, DVRs, NAS, IoT devices, and firewalls, exploiting 66 known CVEs including Log4Shell, Apache ActiveMQ, Citrix NetScaler, Ivanti, and ServiceNow vulnerabilities) which serves as Flax Typhoon's ORB network providing low-cost deniable C2 infrastructure; September 18, 2024 FBI court-authorized takedown neutralized the botnet's C2 (w8510.com domain, 1.2-million-record MySQL management database, Integrity Tech's Sparrow management application)

primary intrusion targeting emphasizes Taiwan (government, education, critical manufacturing, IT, telecommunications, academia, diplomatic) aligned with PRC cross-strait intelligence priorities, with secondary targeting across Hong Kong, Southeast Asia, North America, and Africa; tradecraft hallmarks include extreme reliance on living-off-the- land and legitimate software with minimal custom malware (the signature SoftEther VPN-over-HTTPS C2 channel masqueraded via vpnbridge.exe renamed to conhost.exe or dllhost.exe), public- facing-vulnerability exploitation as primary initial access, LSASS / SAM credential dumping followed by Pass-the-Hash lateral movement, China Chopper web shells, and WinRM / WMIC living-off-the-land lateral movement.

china confidence: high 22 aliases

Profile

Flax Typhoon (Ethereal Panda / RedJuliett / Storm-0919 / UNC5007 / Taifa Typhoon) is a Chinese state-sponsored cyber-espionage actor active since at least mid-2021, formally attributed to operations of Integrity Technology Group (Integrity Tech), a Beijing-based PRC commercial cybersecurity company sanctioned by US Treasury OFAC on January 3, 2025 for its role in Flax Typhoon intrusions. The September 18, 2024 FBI/NSA/CNMF/Five Eyes joint cybersecurity advisory AA24-262A established the Integrity Tech attribution.

an unsealed FBI affidavit documented that Integrity Tech is 'responsible, at least in part, for the computer intrusion activities collectively attributed to Flax Typhoon.' This makes Flax Typhoon one of the most clearly attributed PRC-state-aligned clusters in the public corpus, with a named commercial contractor operating under PRC state tasking, paralleling the i-SOON-revealed MSS commercial-contractor model. Flax Typhoon's distinguishing operational characteristic is the operation of the Raptor Train botnet, one of the largest and most persistent state-aligned botnets ever publicly documented. Active since mid-2021, Raptor Train grew from approximately 60,000 compromised devices in 2023 to over 260,000 by mid-2024, built primarily from compromised SOHO routers, IP cameras, DVRs, network-attached storage, IoT devices, and firewalls, exploiting 66 known CVEs in public-facing devices including Log4Shell, Apache ActiveMQ, Citrix NetScaler, Ivanti Sentry and Endpoint Manager, and ServiceNow. Raptor Train serves as Flax Typhoon's operational relay box (ORB) network, providing low-cost, low-risk, deniable C2 infrastructure that obscures attribution and routes intrusion activity through compromised global infrastructure. The September 18, 2024 FBI court-authorized takedown of Raptor Train's primary C2 infrastructure (including remote malware removal from compromised devices and seizure of the w8510.com C2 domain with its upstream 1.2-million-record MySQL botnet-management database and the Sparrow application developed by Integrity Tech) represented the first major coordinated takedown of a PRC-state-aligned ORB network. Primary intrusion targeting consistently emphasizes Taiwan (government agencies, education, critical manufacturing, information technology, telecommunications, academia, and diplomatic entities) aligned with PRC cross-strait intelligence priorities. Hong Kong, Southeast Asia (Philippines, Vietnam, Thailand, Malaysia, Indonesia, Singapore), North America, and Africa form secondary targeting regions. The Raptor Train botnet's compromised devices span a global footprint, victim devices observed in North America, South America, Europe, Africa, Southeast Asia, and Australia. Tradecraft hallmarks distinguish Flax Typhoon from other PRC clusters: (a) extreme reliance on living-off-the-land (LOLBins) and legitimate software with minimal use of custom malware, Microsoft characterized this as 'using legitimate software to quietly access' victim organizations.

(b) signature use of SoftEther VPN as the C2 channel, the actor renames vpnbridge.exe to conhost.exe or dllhost.exe to masquerade as legitimate Windows components, then uses SoftEther's VPN-over-HTTPS mode to encapsulate Ethernet packets into compliant HTTPS traffic on TCP port 443 (extremely difficult to differentiate from legitimate HTTPS)

(c) initial access primarily through public-facing vulnerability exploitation rather than spear-phishing, 66 known CVEs documented in Zafran tracking.

(d) heavy LSASS / SAM credential dumping via Mimikatz followed by Pass-the-Hash lateral movement.

(e) China Chopper web shells for persistence; (f) Windows Remote Management (WinRM) and WMIC for living-off- the-land lateral movement.

(g) MS16-075 (legacy) leveraged for privilege escalation.

(h) the ORB / botnet operational relay infrastructure as the defining distinguishing capability. Note on PRC cluster boundaries: Flax Typhoon's targeting profile (Taiwan-focused intelligence collection) operationally complements but is distinct from Volt Typhoon (US critical- infrastructure pre-positioning), Salt Typhoon (US telecom and CALEA compromise), and Gallium (global telecom CDR collection). Together these clusters form the modern Chinese state-actor ORB-network and telecom-and-pre-positioning operational ecosystem documented by Microsoft's Typhoon taxonomy and the multiple FBI/NSA/CNMF joint advisories of 2023-2025.

Aliases

22
flax typhoonflaxtyphoonethereal pandaetherealpandaredjuliettred juliettred julietredjulietstorm-0919storm 0919unc5007unc 5007integrity technology groupintegrity techintegrity_techraptor trainraptor_trainsparrowtaifa typhoontaifa_typhoonmssprc state sponsored

Notable Campaigns

9
2025-2026Post-Takedown Continued Operations (2025-2026)
2025US Treasury OFAC Sanctions on Integrity Technology Group (January 3, 2025)
2024Recorded Future RedJuliett Taiwan Intensification (June 2024)
2024Black Lotus Labs Raptor Train Botnet Disclosure (Lumen September 18, 2024)
2024FBI Court-Authorized Botnet Takedown Operation (September 18, 2024)
2024i-SOON Leak and Integrity Tech Competition Context (February-September 2024)
2023Microsoft Flax Typhoon Initial Public Disclosure (August 24, 2023)
2023CrowdStrike ETHEREAL PANDA Disclosure (February 2023)
2023SecurityScorecard STRIKE Team Infrastructure Discovery (August 2023)

Attribution & Reporting

Attributed by
FBICISANSAUS Cyber CommandCyber National Mission Force (CNMF)US Department of JusticeUS Department of TreasuryUS Department of Treasury OFACUS Department of StateUK NCSCAustralia ACSCCanadian Centre for Cyber SecurityNew Zealand NCSCFive EyesTaiwan NCSSTTaiwan TWNCERTMicrosoftMicrosoft Threat Intelligence Center (MSTIC)MandiantGoogle Cloud Threat IntelligenceCrowdStrikeRecorded FutureInsikt GroupSecurityScorecard STRIKE TeamBlack Lotus Labs (Lumen)SentinelOneTrend MicroCheck Point ResearchCisco TalosPalo Alto Networks Unit 42Symantec / BroadcomVolexitySOCRadarNatto TeamZafran
Key reporting
reportMicrosoft Threat Intelligence: Flax Typhoon Using Legitimate Software to Quietly Access Taiwanese Organizations (August 24, 2023)
reportCrowdStrike: ETHEREAL PANDA Adversary Profile (February 2023)
reportCrowdStrike Global Threat Report (multiple years)
reportRecorded Future / Insikt Group: RedJuliett Targets Taiwan Strategic Cyber Operations (June 2024)
reportSecurityScorecard STRIKE Team: SecurityScorecard Identifies Possible Flax Typhoon Infrastructure (August 2023)
reportBlack Lotus Labs / Lumen: Derailing the Raptor Train (September 18, 2024)
reportCISA / FBI / NSA / CNMF / Five Eyes Joint Cybersecurity Advisory: People's Republic of China-Linked Cyber Actors Hide in Router Botnet (AA24-262A, September 18, 2024)
reportUS DOJ: Court-Authorized Operation Disrupts Worldwide Botnet Used by People's Republic of China State-Sponsored Hackers (September 18, 2024)
reportUS Treasury OFAC JY-2769: Treasury Sanctions Technology Company for Support to Malicious Cyber Group (Integrity Technology Group designation, January 3, 2025)
reportNatto Team: Flax Typhoon-Linked Company Integrity Technology, A Competitor, Business Partner and Client of i-SOON (September 25, 2024)
reportAustralia ACSC: Defending Against China-Nexus Covert Networks of Compromised Devices (2025)
reportUK NCSC: PRC State-Linked Actors Hide in Botnets (2024)
reportSOCRadar: Dark Web Profile, Flax Typhoon
reportZafran: Flax Typhoon Vulnerability Exploitation Analysis
reportBank Info Security: US Sanctions Beijing Company for Flax Typhoon Hacking (January 3, 2025)
reportCouncil on Foreign Relations: Flax Typhoon Cyber Operations Tracker
reportEuRepoC: APT Profile, Flax Typhoon

Operational

State sponsor

People's Republic of China (PRC). The September 18, 2024 FBI/NSA/CNMF/Five Eyes joint cybersecurity advisory and the January 3, 2025 US Treasury OFAC sanctions against Integrity Technology Group (Integrity Tech), a Beijing-based cybersecurity company, formally established the attribution. FBI cyber investigator assessment in unsealed US court documents stated Integrity Tech is 'responsible, at least in part, for the computer intrusion activities collectively attributed to Flax Typhoon.' Integrity Tech operates the Raptor Train botnet infrastructure used to control Flax Typhoon operations and has documented links to the PRC government including Chinese state-investment-fund financing.

Motivations
espionage, long_term_access_positioning, intelligence_gathering, taiwan_focused_intelligence, cross_strait_intelligence, critical_infrastructure_positioning, botnet_operations, orb_network_operations, operational_relay_box_infrastructure, geopolitical_collection, regional_dominance
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)36/60 · 60%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

11 mapped
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin