Chinese state-sponsored hackers, identified as the Flax Typhoon group, maintained undetected access to a target environment for over a year by exploiting a feature in the ArcGIS geographic information system (GIS) software. ArcGIS, developed by Esri, is widely used by municipalities, utilities, and infrastructure operators for managing spatial and geographic data. The attackers leveraged valid administrator credentials to access a public-facing ArcGIS server, which was connected to an internal server, allowing them to upload a malicious Java-based Server Object Extension (SOE). This SOE acted as a web shell, accepting base64-encoded commands via a REST API parameter and executing them on the internal server, masquerading as routine operations. The web shell was protected by a hardcoded secret key, ensuring exclusive access for the attackers. Researchers at ReliaQuest, who discovered the intrusion, have moderate confidence that Flax Typhoon was responsible, based on the tactics and infrastructure observed. To further entrench their presence, the attackers used the malicious SOE to install SoftEther VPN Bridge on the compromised system, registering it as a Windows service for persistence. The VPN established an outbound HTTPS tunnel to attacker-controlled infrastructure, blending in with legitimate traffic on port 443 and enabling continued access even if the SOE was removed. This allowed the threat actors to scan the local network, move laterally, and potentially exfiltrate sensitive data. The attack chain was described as unusually clever, as it allowed the group to maintain access even if the victim attempted to restore from backups. Flax Typhoon has a history of targeting organizations in the U.S., Europe, and Taiwan, and this campaign demonstrates their ability to weaponize legitimate software features for long-term espionage. The use of ArcGIS’s extensibility through SOEs provided a stealthy and persistent foothold, complicating detection and remediation efforts. The attackers’ operational security was enhanced by the use of hardcoded secrets and encrypted communications. The campaign highlights the risks associated with exposing administrative interfaces of widely used enterprise software to the internet. ReliaQuest’s findings underscore the importance of monitoring for unusual SOE deployments and outbound VPN connections from critical infrastructure. The incident also illustrates the broader trend of advanced persistent threat (APT) groups abusing legitimate software features to evade detection. Organizations using ArcGIS and similar platforms are advised to audit their server configurations, restrict administrative access, and monitor for anomalous activity. The persistence and sophistication of the Flax Typhoon group reinforce the need for layered security controls and regular threat hunting in environments with high-value data. This incident serves as a warning for all organizations relying on extensible enterprise software, emphasizing the need for vigilance against supply chain and feature abuse attacks.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Following disclosure, reporting highlighted recommended remediation steps including isolating ArcGIS servers, rotating credentials, verifying SOEs and SOIs for unauthorized changes, and rebuilding from clean media. The incident also prompted updates to ArcGIS-related defensive guidance and calls for stronger code-integrity validation.
Multiple security outlets publicly reported in mid-October 2025 that the China-backed group Flax Typhoon had abused ArcGIS Server as a long-term backdoor. The reporting consolidated attribution, tradecraft details, and the persistence mechanism used in the intrusion.
The malicious ArcGIS component was embedded in system backups, meaning restoration from affected backups could reintroduce the backdoor. This made standard recovery plans ineffective unless organizations rebuilt from known-good media.
After establishing persistence, the attackers targeted high-value IT workstations, harvested credentials, and moved laterally within the network. Reporting also says they deployed a renamed SoftEther VPN executable and relied on living-off-the-land techniques to avoid detection.
The malicious ArcGIS SOE allowed Flax Typhoon to persist in the compromised environment for more than a year while blending in with normal server operations. The backdoor reportedly included a hardcoded key for exclusive control and could survive routine recovery efforts.
A China-linked threat group identified as Flax Typhoon modified a legitimate ArcGIS Server Java server object extension (SOE) to function as a covert web shell. The attackers used the trusted geospatial application itself as a backdoor to gain stealthy access to the victim environment.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcegovinfosecurity.com
Open sourcesecurityaffairs.com
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourcedarkreading.com
Open sourcecyberscoop.com
Open sourcesecurityboulevard.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.