Cyber overview
Cyber threat actor

Flax Typhoon

Integrity Technology Group (Beijing), MSS contractor · active since Mid-2021

Built and operated the Raptor Train IoT botnet (260k+ devices) used for intermediate routing and operational obfuscation. Targets Taiwan especially.

Aliases
Ethereal Panda
Primary targets
Taiwan government Education Manufacturing IoT/SOHO routers globally

MITRE ATT&CK techniques

3 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

TacticTechniqueProcedureTargetsCitation
Initial AccessT1190
Exploit Public-Facing Application
Exploited VPN and IIS public-facing apps to enter Taiwan government and education networks.
Taiwan gov/edu/manufacturingMicrosoft Flax Typhoon
PersistenceT1219
Remote Access Software (SoftEther/RMM)
Used SoftEther VPN and Sysinternals for stealth persistence instead of custom malware.
-Microsoft Flax Typhoon
Command & ControlT1090.003
Multi-hop Proxy (Raptor Train botnet)
Operated the Raptor Train IoT botnet (~260k SOHO devices) as a relay layer for Chinese state operators.
Global IoT/SOHO routersFBI takedown announcement

Curated incidents

  1. 2024-09-18·IoT / Critical Infrastructure·Global
    Raptor Train botnet (260k devices) disrupted by FBI

    Court-authorized operation neutralized C2 used to target Taiwan and US.

Live feed mentions
  1. Wed, 18 Sep 2024 15:00:00 GMT · US Department of Justice
    Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors