Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Flax Typhoon

Also known as: Ethereal Panda, Storm-0919

Description

Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan. They conduct espionage campaigns and focus on gaining and maintaining long-term access to networks using minimal malware. Flax Typhoon relies on tools built into the operating system and legitimate software to remain undetected. They exploit vulnerabilities in public-facing servers, use living-off-the-land techniques, and deploy a VPN connection to maintain persistence and move laterally within compromised networks.

AI Analysis

· 2 weeks ago

Executive Summary

Flax Typhoon is a suspected Chinese state-sponsored threat actor primarily targeting organizations in Taiwan through espionage campaigns. The group focuses on long-term network access using minimal malware and operates discreetly by leveraging built-in OS tools and legitimate software.

Goals & Targeting

Flax Typhoon's primary goal appears to be espionage, targeting sectors in Taiwan likely related to government, military, or business. Their targeting of public-facing servers suggests a focus on gaining access to sensitive information while remaining undetected.

Enhanced Description

Flax Typhoon, also known as Ethereal Panda or Storm-0919, is a Chinese state-sponsored actor targeting mainly Taiwanese organizations for espionage. They employ sophisticated techniques such as exploiting server vulnerabilities and using living-off-the-land methods to maintain persistence. Their use of VPNs for C2 communication underscores their focus on stealth and long-term access. Despite being first identified in 2016 or later, they remain active with no known end.

Key Capabilities

  • Exploitation via server vulnerabilities
  • Living-off-the-land techniques
  • Use of VPNs for C2

MITRE ATT&CK Tactics

Initial Access
Lateral Movement

ATT&CK Techniques

T1059.003
T1003
T1078

Software / Tooling

Windows Built-in Tools
Legitimate Software

Campaigns & Victims

Flax Typhoon is active with noted campaigns in Taiwan, focusing on long-term access. Their operations include OS tool abuses and VPN usage, likely maintaining persistence across multiple targets.

IOC Patterns

  • Exploitation of public-facing servers
  • C2 via VPN connections
  • Leveraging OS tools

Recommended Actions

  • Monitor OS tool activity
  • Segment critical networks
  • Patch server vulnerabilities
  • Implement EDR solutions

Suggested Tags

APT
espionage
Taiwan

Confidence Assessment

High confidence in their state sponsorship and targeting focus, but details on tools and campaigns are inferred.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
Taiwan

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.