Flax Typhoon is a China-linked state-sponsored threat actor, also tracked as Ethereal Panda and by Microsoft as Storm-0919 prior to formal naming. The group has been active since at least 2021 and is associated with cyber espionage, long-term persistence, and pre-positioning activity against organizations in Taiwan, the United States, and other regions. Reported targets include government agencies, education, information technology, telecommunications, critical manufacturing, and critical infrastructure sectors such as energy, water, and communications. Activity attributed to the group has also been linked to broader strategic targeting associated with Taiwan-related geopolitical objectives. Flax Typhoon is notable for operational use of compromised edge infrastructure to conceal intrusions and relay malicious traffic. The actor has been tied to the large Raptor Train botnet, which consisted of hundreds of thousands of compromised SOHO routers, cameras, DVRs, NAS devices, and other IoT equipment. That infrastructure was used as an operational relay network to disguise attacker origin, blend malicious traffic with normal regional traffic, and support follow-on intrusion activity. U.S. authorities and private-sector reporting have linked the botnet and related infrastructure to Integrity Technology Group, a Beijing-based company described as supporting or controlling infrastructure used in activity attributed to Flax Typhoon. The group’s tradecraft includes exploitation of internet-facing devices and services, abuse of external remote services, protocol tunneling, use of VPN software for persistence and evasion, web shell deployment, and living-off-the-land command execution. Reporting has also associated the actor with persistence through malicious ArcGIS Server Object Extensions in a compromise of ArcGIS infrastructure, and with IIS-focused intrusion tradecraft that overlaps with other China-linked clusters. Observed behaviors include use of custom web shells, encrypted and obfuscated command channels, DNS-based signaling, in-memory loading of tooling, timestomping, and repeated efforts to maintain access over extended periods. Flax Typhoon has also been associated with data theft and with maintaining year-long access in victim environments. The actor is widely assessed as part of the broader PRC cyber ecosystem that combines state direction with contractor or commercial support. Public reporting has described overlap between Flax Typhoon operations and infrastructure provisioned by private-sector entities, reinforcing assessments that some Chinese intrusion sets rely on shared or leased botnet and relay capabilities rather than building all infrastructure independently. Flax Typhoon is therefore significant not only as an espionage actor, but also as an example of China’s use of commercialized support layers for covert access, operational security, and potential disruptive cyber operations against foreign critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
There was also widespread, global targeting, such as a government agency in Kazakhstan, along with more targeted scanning and likely exploitation attempts against vulnerable software including Atlassian Confluence servers and Ivanti Connect Secure appliances (likely via CVE-2024-21887) in the same sectors.
VulnCheck observed an attacker in the wild using mount as a “download and execute” GTFOBin while attempting to exploit Hikvision CVE-2021-36260... CVE-2021-36260 is a command injection vulnerability affecting the /SDK/webLanguage endpoint.
CISA first warned of the issues in September, when it ordered all agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA).
CISA first warned of the issues in September, when it ordered all agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA).
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among well-known China-nexus APTs mentioned in Project ORBITAL as part of the broader adoption of ORB networks.
Chinese espionage cluster described as maintaining access in foreign critical infrastructure as banked access for later contingency operations.
State-sponsored cluster mentioned as a user of the Raptor Train botnet infrastructure.
Intrusion activity linked to a contractor-supported model in which Integrity Technology Group developed the Raptor Train botnet used to support operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.