APT PRC State-Sponsored Active since 2021

Flax Typhoon

Taiwan-focused espionage expanding to broader targets. IoT botnet operations via compromised SOHO routers.

Scroll

Flax Typhoon is a PRC state-sponsored threat group that has primarily targeted Taiwanese organizations across government, education, critical manufacturing, and IT sectors. The group has expanded operations to include IoT botnet development using compromised SOHO routers and network devices.

AttributeDetail
NamesFlax Typhoon / Ethereal Panda
AttributionPRC State-Sponsored
Active Since2021
Primary FocusTaiwan-focused espionage expanding to broader targets. IoT botnet operations via compromised SOHO routers.

Overview

Flax Typhoon is a PRC state-sponsored threat group that has primarily targeted Taiwanese organizations across government, education, critical manufacturing, and IT sectors. The group has expanded operations to include IoT botnet development using compromised SOHO routers and network devices.

Attribution

Flax Typhoon / Ethereal Panda is attributed to PRC State-Sponsored, active since at least 2021. Taiwan-focused espionage expanding to broader targets. IoT botnet operations via compromised SOHO routers.

Notable Campaigns

MITRE ATT&CK Mapping

Technique IDTechniqueConfidence
T1190Exploit Public-Facing ApplicationHigh
T1078Valid AccountsHigh
T1021Remote ServicesHigh
T1059Command and Scripting InterpreterHigh
T1105Ingress Tool TransferHigh

Detection & Defense

Recommended Defenses

Monitor for the TTPs listed above using your SIEM and EDR platforms. Prioritize patching of internet-facing applications and enforce MFA on all remote access. Mjolnir Security provides continuous threat hunting and monitoring for Flax Typhoon activity patterns.

Mjolnir Security — Threat Intelligence & Response

Mjolnir Security provides 24/7 threat monitoring, incident response, and threat intelligence services. Contact us for threat hunting specifically targeting Flax Typhoon TTPs in your environment.

Threat Hunting Incident Response Threat Intelligence SOC-as-a-Service

mjolnirsecurity.com — 24/7 Incident Response Hotline: +1 833 403 5875