Flax Typhoon is a China-linked state-sponsored threat actor publicly associated with cyber espionage, long-term network access, and pre-positioning activity against critical infrastructure and other strategic sectors. The group has been active since at least 2021 and is widely tracked under the aliases Ethereal Panda and Storm-0919. Flax Typhoon has been linked to operations directed against Taiwan as well as U.S. and other foreign organizations, with targeting that includes government, education, information technology, telecommunications, critical manufacturing, and broader critical infrastructure sectors such as power, water, and communications. The actor is notable for combining traditional espionage tradecraft with large-scale abuse of edge and consumer devices. Flax Typhoon has been tied to the Raptor Train botnet, a large multi-tiered network of compromised small-office/home-office routers, cameras, recorders, network-attached storage devices, and other IoT equipment used to conceal malicious traffic, support intrusion operations, and preserve disruptive options including distributed denial-of-service capability. U.S. authorities and private-sector researchers have linked this infrastructure to Integrity Technology Group, a Beijing-based company assessed to have developed and controlled botnet capabilities used in support of Flax Typhoon activity. This relationship is frequently cited as an example of the PRC’s contractor-enabled cyber ecosystem, in which private firms provide tooling, infrastructure, and operational support to state-directed campaigns. Flax Typhoon’s intrusion tradecraft emphasizes stealth, persistence, and use of legitimate or difficult-to-distinguish network paths. Reported techniques include exploitation of internet-facing network appliances and edge devices, use of compromised IoT infrastructure as relay nodes, protocol tunneling, abuse of external remote services, and use of VPN technologies such as SoftEther VPN for persistence and evasion. The group has also been associated with command obfuscation, web shell deployment, and living-off-the-land style post-compromise activity. In one reported intrusion, activity attributed to Flax Typhoon maintained year-long access to an ArcGIS Server environment by abusing Server Object Extensions to establish a web-shell-like backdoor and persistent remote code execution. Overlapping tradecraft has also been noted in other China-linked IIS-focused intrusions, though not all such clusters are conclusively the same actor. Operational objectives attributed to Flax Typhoon include intelligence collection, access maintenance, and preparation for potential disruptive action during a geopolitical crisis. Multiple government assessments characterize the group’s activity as consistent with broader PRC efforts to pre-position inside foreign critical infrastructure, especially in scenarios involving heightened tensions over Taiwan. Taiwan has identified Flax Typhoon among the Chinese groups involved in sustained targeting of critical sectors, including energy, healthcare, communications, government, and technology. U.S. and allied reporting has similarly described the actor as part of a wider pattern of Chinese campaigns seeking durable access to strategic networks rather than conducting only short-term espionage. Known aliases include Ethereal Panda and Storm-0919. Flax Typhoon is distinct from other China-linked “Typhoon” clusters such as Volt Typhoon, Salt Typhoon, and Silk Typhoon, though these actors are often discussed together because they reflect related PRC strategic priorities: espionage, infrastructure access, telecommunications compromise, and use of covert intermediary infrastructure. Flax Typhoon is best understood as a PRC state-sponsored espionage and access actor with demonstrated reliance on contractor-supported botnet infrastructure and a focus on covert persistence in strategically important networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
There was also widespread, global targeting, such as a government agency in Kazakhstan, along with more targeted scanning and likely exploitation attempts against vulnerable software including Atlassian Confluence servers and Ivanti Connect Secure appliances (likely via CVE-2024-21887) in the same sectors.
VulnCheck observed an attacker in the wild using mount as a “download and execute” GTFOBin while attempting to exploit Hikvision CVE-2021-36260... CVE-2021-36260 is a command injection vulnerability affecting the /SDK/webLanguage endpoint.
CISA first warned of the issues in September, when it ordered all agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA).
CISA first warned of the issues in September, when it ordered all agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA).
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese espionage cluster described as maintaining access in foreign critical infrastructure as banked access for later contingency operations.
State-sponsored cluster mentioned as a user of the Raptor Train botnet infrastructure.
Intrusion activity linked to a contractor-supported model in which Integrity Technology Group developed the Raptor Train botnet used to support operations.
China-linked threat actor referenced for similar base64-encoded command usage, suggesting overlap in tradecraft with OP-512.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.