Flax Typhoon, also known as Earth Naga, RedJuliett, and Ethereal Panda, is a China-aligned advanced persistent threat group active since at least 2021. The group has conducted long-term cyber-espionage operations against government agencies, telecommunications providers, military-related manufacturers, technology companies, media organizations, and academic institutions. Its targeting has been concentrated on Taiwan, while also extending across the broader Asia-Pacific region, NATO member countries, and Latin America. The actor is associated with follow-on exploitation in collaborative intrusion chains in which another China-aligned group, Earth Estries, provides access to already compromised environments. In this operating model, Earth Naga functions as the downstream access user, receiving established footholds for subsequent exploitation and persistence. This collaboration has been described as a form of access-sharing distinct from conventional initial access brokerage because the downstream actor inherits access to internal assets after compromise and persistence are already in place. Earth Naga has been linked to use of ShadowPad and Draculoader, and to intrusion activity involving DLL sideloading, post-compromise deployment through existing sessions, and abuse of compromised credentials for internal movement. Reported operations also include activity against mail and edge-facing infrastructure, including exploitation of vulnerable internet-facing appliances and subsequent attempts to pivot deeper into victim networks over SSH and SMB. The group’s tradecraft reflects a mature espionage-oriented intrusion set focused on maintaining access, expanding control inside victim environments, and enabling sustained intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-aligned cyberespionage group focused heavily on Taiwan and other strategic targets, observed receiving shared access from Earth Estries and using ShadowPad and related infrastructure in coordinated intrusions.
Threat actor receiving initial access from Earth Estries for subsequent exploitation activity.
APT group referenced as using Draculoader and historically targeting government agencies in Southeast Asia and elsewhere.
China-aligned cyberespionage actor described collaborating with another China-aligned group via access-brokering (‘pass-as-a-service’) to enable continued exploitation; targets include government and telecommunications, with recent focus on retail and government-related orgs in APAC.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.