Azurite is an OT-focused cyber threat group identified in 2025 and assessed to overlap with Flax Typhoon, a China-linked intrusion set. The group is associated with campaigns against critical infrastructure and industrial organizations, with a particular emphasis on gaining long-term access to OT engineering workstations and stealing operationally relevant files. Reported collection priorities include engineering and process documentation such as network diagrams, alarm data, and process information, indicating an interest in developing detailed operational understanding of targeted environments rather than conducting opportunistic theft alone. Azurite has been observed targeting organizations in manufacturing, defense, automotive, electric power, oil and gas, and government. Its victimology spans the United States, Europe, and the Asia-Pacific region. The group’s tradecraft, as publicly described, centers on persistence in OT-adjacent systems and exfiltration of operational data from engineering workstations, which are high-value assets for understanding industrial processes and enabling follow-on activity. The available reporting supports assessment of a China nexus through overlap with Flax Typhoon, but does not provide sufficient high-confidence detail on broader tooling, intrusion chain specifics, or subordinate clusters beyond that overlap.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OT-focused activity cluster overlapping with Flax Typhoon, targeting OT engineering workstations to establish long-term access and exfiltrate data.
Dragos-tracked activity cluster newly observed targeting ICS/OT environments (no further details provided in the content).
Named by Dragos as a newly identified (2025) threat group targeting OT environments; no additional activity details provided in the content.
OT-focused long-term access and operational data theft (engineering workstation access; exfiltration of diagrams/alarm/process data) to support downstream capability development; activity overlaps with Flax Typhoon.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.