operational Offensive Operationshigh

Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors

Wed, Sep 18, 2024, 03:00 PM UTC·Sep 18, 2024· Defense / Military (DOD)

Summary

Bottom line: the Federal Bureau of Investigation removed malware from roughly 260,000 consumer routers, cameras and storage devices used as attack relay infrastructure by Flax Typhoon. Consumer devices inside United States address space are strategic terrain and are being cleaned by court order.

Key claims· extracted from reporting

  • Bottom line: the Federal Bureau of Investigation removed malware from roughly 260,000 consumer routers, cameras and storage devices used as attack relay infrastructure by Flax Typhoon.Med · 30%
    numbernamed entity×4
  • Consumer devices inside United States address space are strategic terrain and are being cleaned by court order.Low · 10%
    named entity×2

Heuristic extraction, verify against the original report before citing.

Tags· click to alert

Key takeaways

The three things worth remembering from this item.

  1. 1Bottom line: Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors[1]
  2. 2Flax Typhoon activity is the driver here, and the objective is what should shape your response, not the tool names.[1][2][3]
  3. 3Defensively, the highest-leverage move is coverage for T1190 · Exploit Public-Facing Application, because it is a behavior class rather than an indicator.[1][2]

Concepts in this story

Each concept opens in layers: plain English, technical, then expert.

Flax Typhoon

China · High tempo

Flax Typhoon is a China linked hacking group. In plain terms, they break into taiwan government, education, manufacturing and stay there. Their goal is to build and operate orb relay infrastructure for obfuscated collection.

Why it matters
Beijing-nexus operations are the pacing threat in US cyber policy: the concern is pre-positioning inside critical infrastructure for use during a crisis, not day-to-day theft.[1][2][3]
Common misconception
That every Chinese intrusion is intellectual property theft. Pre-positioning groups deliberately steal nothing, which is exactly why they go unnoticed.
MITRE ATT&CK G1023 Cyber Kill ChainNIST CSF 2.0, Identify, Detect, Respond
Sources for this concept
  1. [1]Flax Typhoon group profile· MITRE ATT&CK G1023
  2. [2]Raptor Train botnet (260k devices) disrupted by FBI· Public incident reporting· 2024-09-18 00:00Z
  3. [3]Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors· US Department of Justice· 2024-09-18 15:00Z

T1190 · Exploit Public-Facing Application

Initial Access · used by 13 tracked groups

Exploit Public-Facing Application is how an attacker initial access works in practice. Edge devices and VPN appliances (Ivanti, Fortinet, Citrix, Cisco) exploited within hours of CVE disclosure.

Why it matters
This is a initial access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1190 Tactic: Initial Access
Sources for this concept
  1. [1]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190
  2. [2]Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors· US Department of Justice· 2024-09-18 15:00Z

T1078 · Valid Accounts

Initial Access · used by 18 tracked groups

Valid Accounts is how an attacker initial access works in practice. Stolen or sprayed credentials used in place of malware, defeating signature-based detection.

Why it matters
This is a initial access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1078 Tactic: Initial Access
Sources for this concept
  1. [1]T1078 · Valid Accounts· MITRE ATT&CK T1078
  2. [2]Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors· US Department of Justice· 2024-09-18 15:00Z

T1090.003 · Proxy: Multi-hop Proxy

Command and Control · used by 4 tracked groups

Proxy: Multi-hop Proxy is how an attacker command and control works in practice. Operational relay box (ORB) botnets of compromised SOHO routers obscure origin.

Why it matters
This is a command and control behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1090.003 Tactic: Command and Control
Sources for this concept
  1. [1]T1090.003 · Proxy: Multi-hop Proxy· MITRE ATT&CK T1090.003
  2. [2]Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors· US Department of Justice· 2024-09-18 15:00Z

T1021.001 · Remote Services: Remote Desktop Protocol

Lateral Movement · used by 4 tracked groups

Remote Services: Remote Desktop Protocol is how an attacker lateral movement works in practice. Credentialed RDP and PsExec movement blending into administrator behavior.

Why it matters
This is a lateral movement behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1021.001 Tactic: Lateral Movement
Sources for this concept
  1. [1]T1021.001 · Remote Services: Remote Desktop Protocol· MITRE ATT&CK T1021.001
  2. [2]Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors· US Department of Justice· 2024-09-18 15:00Z
Sources for these takeaways
  1. [1]Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors· US Department of Justice· 2024-09-18 15:00Z
  2. [2]Flax Typhoon group profile· MITRE ATT&CK G1023
  3. [3]Raptor Train botnet (260k devices) disrupted by FBI· Public incident reporting· 2024-09-18 00:00Z
  4. [4]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190

Knowledge check

Five questions. Answers explain the reasoning, not just the result.

Question 1 of 5

Which nexus is Flax Typhoon attributed to in public reporting?

Question 2 of 5

Which sector is a primary target for Flax Typhoon?

Question 3 of 5

Which ATT&CK tactic does T1190 (Exploit Public-Facing Application) belong to?

Question 4 of 5

Which ATT&CK tactic does T1078 (Valid Accounts) belong to?

Question 5 of 5

Which ATT&CK tactic does T1090.003 (Proxy: Multi-hop Proxy) belong to?

Answer all 5 to check.
Estimated mastery
First time on this material.
New · 0/100