Flax Typhoon is a People’s Republic of China state-sponsored cyber-espionage actor active since at least 2021. Also tracked as Ethereal Panda and Storm-0919, it primarily targets organizations in Taiwan, particularly government, education, critical manufacturing, and information-technology sectors; activity has also been observed across Southeast Asia, North America, and Africa. The actor has exploited known vulnerabilities in public-facing applications for initial access, used China Chopper web shells, and relied extensively on living-off-the-land and hands-on-keyboard tradecraft. Flax Typhoon has used SoftEther VPN infrastructure and compromised small-office/home-office and IoT devices to proxy and obscure operational traffic. In 2024, U.S. authorities disrupted a large IoT botnet associated with the actor that consisted of hundreds of thousands of compromised devices and was reportedly used to provide proxy infrastructure for Chinese government customers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
There was also widespread, global targeting, such as a government agency in Kazakhstan, along with more targeted scanning and likely exploitation attempts against vulnerable software including Atlassian Confluence servers and Ivanti Connect Secure appliances (likely via CVE-2024-21887) in the same sectors.
VulnCheck observed an attacker in the wild using mount as a “download and execute” GTFOBin while attempting to exploit Hikvision CVE-2021-36260... CVE-2021-36260 is a command injection vulnerability affecting the /SDK/webLanguage endpoint.
CISA first warned of the issues in September, when it ordered all agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA).
CISA first warned of the issues in September, when it ordered all agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA).
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentionné uniquement comme contexte historique d’une précédente neutralisation d’un botnet IoT.
Mentioned only as a prior threat-actor disruption; no operational details are provided in this reference.
Mentioned only as a comparison to prior U.S. takedown operations.
Mentioned in comparison to a separate 2024 disruption of an IoT botnet it allegedly operated.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.