Flax Typhoon

Threat Actor updated 3 days ago (2024-11-20T17:39:40.563Z)
Download STIX
Preview STIX
Flax Typhoon is a threat actor reportedly linked to China that has been actively targeting Taiwan, as well as other regions globally. This group, also known by aliases such as RedJuliett and Ethereal Panda, has been implicated in cyberespionage activities against critical infrastructure entities, government organizations, and private companies. They are one of several Advanced Persistent Threats (APTs) sponsored by China, including Salt Typhoon and Volt Typhoon, which Microsoft has publicly disclosed. Flax Typhoon's activities have been observed across different sectors, including IT, military, and governmental interests around the South China Sea. A distinctive feature of Flax Typhoon's operations is its extensive use of SoftEther VPN, an open-source, cross-platform VPN software favored by many cybercriminals. The group has been observed switching from its full-featured backdoor to using the SoftEther VPN Bridge on machines of governmental organizations in the EU. Furthermore, they've deployed SoftEther VPN servers at telecommunications operators in Africa. This shift towards common VPN software aligns with tactics observed in other China-backed APTs such as Gallium and Webworm. Recently, Lumen Technologies' threat intelligence group, Black Lotus Labs, detailed a botnet linked to Flax Typhoon that used a modified version of the Mirai internet-of-things malware to compromise routers, modems, IP cameras, NAS servers, and digital video recorders. The experts believe this botnet is controlled by Flax Typhoon, further cementing the group's reputation for stealthy and persistent cyber operations. Flax Typhoon's activities pose a significant threat to global cybersecurity, highlighting the need for robust defense mechanisms against such sophisticated attacks.
Description last updated: 2024-11-15T16:05:50.166Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Ethereal Panda is a possible alias for Flax Typhoon. Ethereal Panda, also known as Flax Typhoon or RedJuliett, is a threat actor believed to be linked to the Chinese government. This group has been involved in various cyber espionage activities targeting organizations primarily in Taiwan. Reports from cybersecurity firms such as Microsoft and CrowdStr
6
Redjuliett is a possible alias for Flax Typhoon. RedJuliett, also known as Flax Typhoon and Ethereal Panda, is a China-linked Advanced Persistent Threat (APT) group that has been reported to control a botnet for malicious activities. This state-sponsored group has been persistently launching espionage attacks on numerous organizations since 2023.
4
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Apt
Vpn
Chinese
Botnet
Malware
Espionage
Windows
Microsoft
Exploit
Lateral Move...
Source
Taiwan
Taiwanese
Web Shell
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The China Chopper Malware is associated with Flax Typhoon. China Chopper is a notorious malware, a harmful program designed to exploit and damage computer systems. It has been primarily used by the threat actor group BRONZE UNION to establish connections to China Chopper web shells on compromised servers, as seen in multiple instances where its code was fouUnspecified
2
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The GALLIUM Threat Actor is associated with Flax Typhoon. Gallium, also known as Alloy Taurus, is a threat actor group that has been associated with significant cyber-espionage campaigns and is believed to have ties with China. The group has been linked to multiple intrusion sets targeting network devices, including routers and servers. Gallium notably tarUnspecified
3
The Volt Typhoon Threat Actor is associated with Flax Typhoon. Volt Typhoon, a cyberespionage cluster sponsored by China, has emerged as a significant threat actor in the cybersecurity landscape. Known for its strong operational security and obfuscation of malware, Volt Typhoon is both a resilient botnet and a warning signal of potential critical infrastructureUnspecified
2
Source Document References
Information about the Flax Typhoon Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
BankInfoSecurity
8 days ago
ESET
16 days ago
DARKReading
16 days ago
BankInfoSecurity
16 days ago
BankInfoSecurity
17 days ago
DARKReading
25 days ago
InfoSecurity-magazine
a month ago
BankInfoSecurity
2 months ago
Securityaffairs
2 months ago
DARKReading
2 months ago
InfoSecurity-magazine
2 months ago
BankInfoSecurity
2 months ago
DARKReading
2 months ago
InfoSecurity-magazine
2 months ago
Securityaffairs
2 months ago
Securelist
3 months ago
Securityaffairs
3 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago