Cyber threat actor
Flax Typhoon
Integrity Technology Group (Beijing), MSS contractor · active since Mid-2021
Built and operated the Raptor Train IoT botnet (260k+ devices) used for intermediate routing and operational obfuscation. Targets Taiwan especially.
Aliases
Ethereal Panda
Primary targets
Taiwan government Education Manufacturing IoT/SOHO routers globally
MITRE ATT&CK techniques
3 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
| Tactic | Technique | Procedure | Targets | Citation |
|---|---|---|---|---|
| Initial Access | T1190 Exploit Public-Facing Application | Exploited VPN and IIS public-facing apps to enter Taiwan government and education networks. | Taiwan gov/edu/manufacturing | Microsoft Flax Typhoon |
| Persistence | T1219 Remote Access Software (SoftEther/RMM) | Used SoftEther VPN and Sysinternals for stealth persistence instead of custom malware. | - | Microsoft Flax Typhoon |
| Command & Control | T1090.003 Multi-hop Proxy (Raptor Train botnet) | Operated the Raptor Train IoT botnet (~260k SOHO devices) as a relay layer for Chinese state operators. | Global IoT/SOHO routers | FBI takedown announcement |
Curated incidents
- 2024-09-18·IoT / Critical Infrastructure·GlobalRaptor Train botnet (260k devices) disrupted by FBI
Court-authorized operation neutralized C2 used to target Taiwan and US.
Live feed mentions
- Wed, 18 Sep 2024 15:00:00 GMT · US Department of JusticeCourt-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors