Flax Typhoon — APT Profile
Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan. They conduct espionage campaigns and focus on gaining and maintaining long-term access to networks using minimal malware. Flax Typhoon relies on tools built into the operating system and legitimate software to remain undetected. They exploit vulnerabilities in public-facing servers, use living-off-the-land techniques, and deploy a VPN connection to maintain persistence and move laterally within compromised networks.Also tracked as
ETHEREAL PANDA, Storm-0919, RedJuliett
IntelFusions coverage (1)
- SOE-phisticated Persistence: How Flax Typhoon Turned ArcGIS Into a Year-Long Backdoor 2026-02-16 · Nation-State
Tools & malware
- elf.nosedive Backdoor
Vendor research
- People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations (JCSA-20240918-001) FBI / Cyber National Mission Force / NSA (Joint Cybersecurity Advisory)
- Derailing the Raptor Train Lumen Black Lotus Labs
- Chinese State-Sponsored RedJuliett Intensifies Taiwanese Cyber Espionage via Network Perimeter Exploitation Recorded Future (Insikt Group)
- Flax Typhoon using legitimate software to quietly access Taiwanese organizations Microsoft