Full Report
The U.S. Department of the Treasury sanctioned Beijing-based cybersecurity vendor Integrity Tech for its role in multiple computer... The post US Treasury sanctions Beijing’s Integrity Tech for Flax Typhoon cyber intrusions on critical infrastructure appeared first on Industrial Cyber.
Analysis Summary
# Threat Actor: Flax Typhoon
## Attribution & Identity
* **Identification:** Chinese malicious state-sponsored cyber group.
* **Known Aliases/Associated Groups:** Sanctions imposed on Beijing-based cybersecurity vendor **Integrity Tech** for supporting Flax Typhoon's intrusion activities. The group is also associated with the espionage campaign known as **Salt Typhoon** targeting U.S. telecommunication firms.
* **Activity Timeline:** Active since at least 2021.
## Activity Summary
Flax Typhoon has been engaged in computer network exploitation activities primarily targeting U.S. critical infrastructure sectors. Between summer 2022 and fall 2023, the group used infrastructure tied to Integrity Tech for exploitation activities, routinely sending and receiving information through these compromised channels. The activity is linked to a broader Chinese espionage campaign that breached at least nine U.S. telecommunications firms (Salt Typhoon). The group actively targets U.S. government systems, including recent targeting of the Treasury's IT infrastructure.
## Tactics, Techniques & Procedures
* Exploiting publicly known vulnerabilities for initial access.
* Leveraging legitimate remote access software to maintain persistent control over compromised networks.
* Maliciously using virtual private network (VPN) software to facilitate access.
* Utilizing remote desktop protocols (RDP) to facilitate access.
* [MITRE ATT&CK IDs were not explicitly provided in the text, only referenced a joint advisory highlighting relevant TTPs.]
## Targeting
* **Sectors:** U.S. critical infrastructure sectors, including telecommunications firms.
* **Geography:** North America, Europe, Africa, and Asia, with a particular focus on Taiwan.
* **Victims:** Multiple organizations within U.S. critical infrastructure; at least nine U.S. telecommunications firms (Salt Typhoon campaign); a California-based entity (multiple servers and workstations compromised in Summer 2023).
## Tools & Infrastructure
* **Malware Families Used:** Not explicitly named, but relied heavily on existing remote access tools.
* **Infrastructure:** Infrastructure tied to sanctioned vendor **Integrity Tech** was utilized between Summer 2022 and Fall 2023 for command and control/communication.
* **Tools:** Legitimate remote access software; VPN software; Remote Desktop Protocols (RDP).
## Implications
Flax Typhoon represents a persistent, state-sponsored threat to U.S. national security, particularly concerning the compromise of critical infrastructure. The enforcement action against Integrity Tech signals a willingness by the U.S. government to use financial tools (OFAC sanctions) to disrupt the supply chain and infrastructure enabling these malicious actors. Continued espionage targeting sensitive sectors highlights ongoing collection efforts by the actor.
## Mitigations
* Harden defenses, especially within critical infrastructure sectors, against threats leveraging known vulnerabilities.
* Scrutinize network activity for indicators of legitimate remote access software (VPNs, RDP) being used maliciously for persistent access.
* Monitor and sever any connections or transactions with entities identified as supporting malicious cyber activity, such as the sanctioned vendor Integrity Tech, due to prohibition on transactions with blocked persons.