Microsoft said the China-backed espionage group Flax Typhoon has quietly compromised organizations in Taiwan by abusing legitimate tools and living-off-the-land techniques, with targeting focused on government, education, critical manufacturing, and information technology. The activity relied on access through public-facing applications, persistence with software such as SoftEther VPN, and proxying through compromised SOHO devices to reduce detection, aligning the campaign with broader PRC cyber operations described in U.S. defense strategy documents.
SecurityScorecard later reported additional infrastructure likely linked to Flax Typhoon by tracing reused TLS certificate SHA-1 fingerprints associated with the group’s SoftEther VPN servers and analyzing partner NetFlow data. Its researchers identified repeated communication between a previously flagged VPN IP, 45.204.1[.]203, and four IP addresses attributed to Fudan University — 202.120.224[.]129, 202.120.224[.]82, 202.120.224[.]114, and 202.120.224[.]116 — raising the possibility of higher-education-linked support infrastructure while noting the university systems could themselves be compromised; the firm urged likely targets to monitor and consider blocking the identified infrastructure.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
On August 24, Microsoft published an analysis of a newly tracked threat actor it calls Flax Typhoon, assessing that it conducts espionage on behalf of the People's Republic of China. Microsoft said the group mainly targeted Taiwanese organizations in government, education, critical manufacturing, and information technology.
The U.S. Department of Defense's 2023 Cyber Strategy described the People's Republic of China as a broad and pervasive cyber espionage threat to the United States and its allies and partners. The strategy also said state control over China's cybersecurity industry and large technology workforce contribute to PRC cyber capabilities.
SecurityScorecard reported that the China-linked espionage group Flax Typhoon has operated since 2021. The group primarily targeted organizations in Taiwan and also appeared in Southeast Asia, North America, and Africa.
SecurityScorecard's STRIKE Team observed repeated communication between Flax Typhoon-linked VPN IP 45.204.1[.]203 and four Chinese IP addresses attributed to Fudan University. The researchers assessed this traffic may indicate a possible link between Flax Typhoon and Fudan University, while noting the university-attributed IPs could also have been compromised.
SecurityScorecard reported additional infrastructure likely used by Flax Typhoon by matching TLS certificate SHA-1 fingerprints from Microsoft's reporting to other SoftEther VPN servers. It identified several likely linked IP addresses, including 92.253.235[.]9, 45.204.1[.]203, 45.195.149[.]164, 182.61.132[.]155, and 103.51.145[.]76.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcesecurityscorecard.com
Open sourcemicrosoft.com
Open sourcemedia.defense.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.