Flax Typhoon — APT Profile

Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan. They conduct espionage campaigns and focus on gaining and maintaining long-term access to networks using minimal malware. Flax Typhoon relies on tools built into the operating system and legitimate software to remain undetected. They exploit vulnerabilities in public-facing servers, use living-off-the-land techniques, and deploy a VPN connection to maintain persistence and move laterally within compromised networks.

Also tracked as

ETHEREAL PANDA, Storm-0919, RedJuliett

IntelFusions coverage (1)

Tools & malware

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions