Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagepersistence-methodcommand-and-control-methodlateral-movement-method

Flax Typhoon Persistence via ArcGIS Server Object Extension Web Shell

Updated 3mo agoFirst seen Oct 14, 20259 sources

Chinese state-sponsored hackers, identified as the Flax Typhoon group, maintained undetected access to a target environment for over a year by exploiting a feature in the ArcGIS geographic information system (GIS) software. ArcGIS, developed by Esri, is widely used by municipalities, utilities, and infrastructure operators for managing spatial and geographic data. The attackers leveraged valid administrator credentials to access a public-facing ArcGIS server, which was connected to an internal server, allowing them to upload a malicious Java-based Server Object Extension (SOE). This SOE acted as a web shell, accepting base64-encoded commands via a REST API parameter and executing them on the internal server, masquerading as routine operations. The web shell was protected by a hardcoded secret key, ensuring exclusive access for the attackers. Researchers at ReliaQuest, who discovered the intrusion, have moderate confidence that Flax Typhoon was responsible, based on the tactics and infrastructure observed. To further entrench their presence, the attackers used the malicious SOE to install SoftEther VPN Bridge on the compromised system, registering it as a Windows service for persistence. The VPN established an outbound HTTPS tunnel to attacker-controlled infrastructure, blending in with legitimate traffic on port 443 and enabling continued access even if the SOE was removed. This allowed the threat actors to scan the local network, move laterally, and potentially exfiltrate sensitive data. The attack chain was described as unusually clever, as it allowed the group to maintain access even if the victim attempted to restore from backups. Flax Typhoon has a history of targeting organizations in the U.S., Europe, and Taiwan, and this campaign demonstrates their ability to weaponize legitimate software features for long-term espionage. The use of ArcGIS’s extensibility through SOEs provided a stealthy and persistent foothold, complicating detection and remediation efforts. The attackers’ operational security was enhanced by the use of hardcoded secrets and encrypted communications. The campaign highlights the risks associated with exposing administrative interfaces of widely used enterprise software to the internet. ReliaQuest’s findings underscore the importance of monitoring for unusual SOE deployments and outbound VPN connections from critical infrastructure. The incident also illustrates the broader trend of advanced persistent threat (APT) groups abusing legitimate software features to evade detection. Organizations using ArcGIS and similar platforms are advised to audit their server configurations, restrict administrative access, and monitor for anomalous activity. The persistence and sophistication of the Flax Typhoon group reinforce the need for layered security controls and regular threat hunting in environments with high-value data. This incident serves as a warning for all organizations relying on extensible enterprise software, emphasizing the need for vigilance against supply chain and feature abuse attacks.

Share:
Flax Typhoon Persistence via ArcGIS Server Object Extension Web Shell
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Oct 15, 20258mo ago

Guidance issued to inspect ArcGIS extensions and rebuild affected systems

Following disclosure, reporting highlighted recommended remediation steps including isolating ArcGIS servers, rotating credentials, verifying SOEs and SOIs for unauthorized changes, and rebuilding from clean media. The incident also prompted updates to ArcGIS-related defensive guidance and calls for stronger code-integrity validation.

Oct 14, 20258mo ago

Public reporting links ArcGIS backdoor activity to Flax Typhoon

Multiple security outlets publicly reported in mid-October 2025 that the China-backed group Flax Typhoon had abused ArcGIS Server as a long-term backdoor. The reporting consolidated attribution, tradecraft details, and the persistence mechanism used in the intrusion.

Compromised backups turn recovery process into reinfection vector

The malicious ArcGIS component was embedded in system backups, meaning restoration from affected backups could reintroduce the backdoor. This made standard recovery plans ineffective unless organizations rebuilt from known-good media.

Oct 14, 20242y ago

Flax Typhoon uses compromised ArcGIS server for lateral movement and credential theft

After establishing persistence, the attackers targeted high-value IT workstations, harvested credentials, and moved laterally within the network. Reporting also says they deployed a renamed SoftEther VPN executable and relied on living-off-the-land techniques to avoid detection.

Attackers maintain covert access in ArcGIS environment for over a year

The malicious ArcGIS SOE allowed Flax Typhoon to persist in the compromised environment for more than a year while blending in with normal server operations. The backdoor reportedly included a hardcoded key for exclusive control and could survive routine recovery efforts.

Flax Typhoon compromises ArcGIS Server and implants malicious SOE

A China-linked threat group identified as Flax Typhoon modified a legitimate ArcGIS Server Java server object extension (SOE) to function as a covert web shell. The attackers used the trusted geospatial application itself as a backdoor to gain stealthy access to the victim environment.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Threat actors
1 linked
Affected products
2 linked
Arcgis ServerArcgis
Organizations
11 linked
ReliaQuestMicrosoft CorporationEsriIntegrity Technology GroupFlax TyphoonCounterpoint ResearchSolarWindsArcgis3cxPrimus PartnersAnkura Consulting
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Flax Typhoon Persistence via ArcGIS Server Object Extension Web Shell | Mallory