Flax Typhoon, also known as Ethereal Panda and tracked by Microsoft as a China-attributed nation-state threat actor, is an espionage-focused group active since at least 2021. The actor has been linked to PRC state-sponsored operations and to infrastructure and support provided by Beijing-based Integrity Technology Group. Flax Typhoon is associated with the use of large botnets built from compromised routers, cameras, DVRs, NAS devices, and other internet-connected edge devices to conceal operator origin, relay malicious traffic, and support intrusion activity against downstream targets. The group has targeted government agencies, telecommunications providers, universities, media organizations, critical manufacturing, information technology organizations, and broader critical infrastructure. Reported victim geography includes the United States and Taiwan, with additional foreign targeting observed elsewhere. Public reporting also ties the actor to campaigns against communications, energy, healthcare, and other critical sectors in Taiwan, as well as U.S. critical infrastructure and technology networks. A defining element of Flax Typhoon tradecraft is Operational Relay Box-style infrastructure and the Raptor Train botnet, which U.S. authorities and private-sector researchers linked to the actor and to Integrity Technology Group. That botnet used compromised SOHO and IoT devices as proxy nodes and attack infrastructure, enabling scanning, exploitation, traffic relaying, and concealment of follow-on operations. The actor has also been associated with management of botnet infrastructure through China Unicom-linked network resources and with contractor-enabled operational support inside China’s broader state cyber ecosystem. Flax Typhoon has demonstrated persistence and post-compromise tradecraft beyond botnet operations. Reporting tied the group to long-term access on ArcGIS Server through malicious Server Object Extensions that enabled remote code execution and durable access. Separate China-linked IIS intrusion activity showed overlaps in command encoding and web-shell tradecraft previously seen in Flax Typhoon incidents, suggesting shared tooling or a common operational playbook within the PRC intrusion ecosystem. The actor has also been linked to use of external remote services and tunneling technologies, including SoftEther VPN, to maintain access and evade detection. The group’s observed behaviors include initial access through exploitation of vulnerable edge devices and internet-facing systems, reconnaissance and scanning, persistence through malicious components and remote-access tooling, defense evasion through layered proxy infrastructure and protocol tunneling, and data theft from victim environments. U.S. and partner governments have described Flax Typhoon as part of a broader Chinese strategy of pre-positioning within foreign critical infrastructure for potential future use during geopolitical crises. During disruption of its botnet infrastructure, China-based operators linked to the activity also attempted a distributed denial-of-service response against FBI operational infrastructure. Flax Typhoon is best understood as a China-linked state-sponsored espionage actor that combines traditional network intrusion with contractor-supported botnet infrastructure, especially compromised consumer and small-office networking equipment, to support stealthy access, persistence, and collection against government, telecom, technology, and critical infrastructure targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
There was also widespread, global targeting, such as a government agency in Kazakhstan, along with more targeted scanning and likely exploitation attempts against vulnerable software including Atlassian Confluence servers and Ivanti Connect Secure appliances (likely via CVE-2024-21887) in the same sectors.
VulnCheck observed an attacker in the wild using mount as a “download and execute” GTFOBin while attempting to exploit Hikvision CVE-2021-36260... CVE-2021-36260 is a command injection vulnerability affecting the /SDK/webLanguage endpoint.
CISA first warned of the issues in September, when it ordered all agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA).
CISA first warned of the issues in September, when it ordered all agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA).
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operated a botnet of compromised routers and other internet-connected devices, using Integrity Tech infrastructure as the control layer.
Operated a botnet of compromised routers and other internet-connected devices, with Integrity Tech infrastructure identified as the control layer.
Referenced as the threat actor linked to operations facilitated by Beijing Integrity Technology Co.; described as targeting government agencies, critical infrastructure, and technology networks globally.
Referenced as the threat actor linked to state-sponsored cyber operations facilitated by Beijing Integrity Technology Co., targeting government agencies, critical infrastructure, and technology networks globally.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.