Full Report
Infecting devices from 2021 until the FBI stepped in
Analysis Summary
# Threat Actor: Flax Typhoon
## Attribution & Identity
* **Actor Name:** Flax Typhoon
* **Associated Groups:** RedJuliett (overlapping activity noted by private sector researchers), "Raptor Train" network operators.
* **Known Associations:** Linked to the **Integrity Technology Group**, a private sector information security firm based in China that reportedly holds contracts with the PRC government.
* **Sponsorship:** Beijing-backed/Chinese government-linked cyber operatives.
## Activity Summary
From 2021 until its disruption by the FBI in late 2024, Flax Typhoon conducted global cyber espionage and network intrusion operations. The group utilized a large-scale botnet consisting of infected IoT devices and routers to obfuscate their origins while scanning for vulnerabilities in critical infrastructure. Their operations focused on establishing long-term persistence within target networks to exfiltrate sensitive data and operational files.
## Tactics, Techniques & Procedures
* **Botnet Operations:** Utilized a Mirai-based botnet to infect internet-connected devices (IoT/routers) to hide true IP addresses and physical locations.
* **Vulnerability Scanning:** Used a proprietary tool called "Microscan" to identify weaknesses in target networks.
* **Exploitation:** Leveraged known vulnerabilities in Microsoft Exchange servers and other software.
* **Persistence:** Established through the use of VPN software and post-compromise tools.
* **Post-Exploitation:** Utilized "FishHub" malware to download additional payloads, list files, compress documents, and exfiltrate data.
* **Specific TTPs:**
* Cross-site scripting (XSS) attacks.
* Password spraying.
* Use of scripts for credential and email exfiltration.
* **MITRE ATT&CK IDs (Inferred from text):**
* T1190 (Exploit Public-Facing Application)
* T1110.003 (Password Spraying)
* T1584.005 (Botnet)
* T1048 (Exfiltration Over Alternative Protocol)
* **Exploited CVEs:**
* CVE-2015-3306
* CVE-2015-5477
* CVE-2016-3081
* CVE-2021-3199
* CVE-2023-22894
## Targeting
* **Sectors:** Critical Infrastructure (Power, Natural Gas), Government agencies, Education (Universities), NGOs, Aviation (Airports), Manufacturing, Defense, and Automotive.
* **Geography:** United States, Taiwan, Japan, Poland, United Kingdom, Australia, Canada, New Zealand, Spain, and the wider Asia-Pacific and European regions.
* **Victims:**
* South Carolina power company.
* Universities in Hsinchu and Puli Township, Taiwan (and ~20 others).
* Taiwanese natural gas and power sector companies.
* Japanese and Polish airports.
* NASA, US Senate, and US Department of Energy (targeted/associated).
## Tools & Infrastructure
* **Malware:**
* **FishHub:** A post-compromise tool/malware downloader.
* **Mirai-based botnet:** Used for proxying traffic and obfuscation.
* **Infrastructure:**
* **Microscan:** Proprietary vulnerability scanning tool.
* **Seized Domains (Defanged):**
* c0cc[.]cc
* 98aicai[.]com
* 98aicode[.]com
* outlook3650[.]com
* youtubecard[.]com
* linkedinns[.]net
## Implications
Flax Typhoon represents a sophisticated "State-as-a-Service" model where the PRC uses private contractors (Integrity Technology Group) to conduct espionage. The group’s focus on critical infrastructure (power, gas, airports) suggests a strategic objective beyond simple data theft, potentially including pre-positioning for disruptive capabilities. The use of widespread IoT botnets complicates attribution and makes traditional IP-based blocking ineffective.
## Mitigations
* **Patch Management:** Prioritize remediation of the specific CVEs listed (CISA KEV catalog), particularly for Microsoft Exchange and edge devices.
* **VPN Security:** Audit VPN logs for unauthorized persistence and ensure all VPN software is fully patched and utilizes MFA.
* **IoT Security:** Secure or decommission legacy internet-facing IoT devices and routers that are susceptible to Mirai-based infections.
* **Network Monitoring:** Monitor for unusual outbound traffic to the identified C2 domains and investigate any use of unauthorized scanning tools like Microscan within the environment.
* **Credential Protection:** Implement robust password policies and MFA to defend against password spraying attacks.