Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-10

Flax Typhoon

Also known as:Integrity Technology Group

As of 2026-10-09, Flax Typhoon is a China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning apt. Also known as Integrity Technology Group. ATT&CK coverage spans 32 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1059.006 (Python), T1110.003 (Password Spraying), T1114.002 (Email Collection: Remote Email Collection).

Tracked threats
22 high
First seen
2026-10-08
Last seen
2026-10-09
ATT&CK techniques
32across 2 of 2 threats
Related CVEs
9Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 2 tracked threat(s) · Categories: APT

Activity timeline

Flax Typhoon appears in 2 tracked threats between and .

ATT&CK techniques observed

32 techniques observed across 2 of 2 tracked threats · Credential Access (5), Command and Control (4), Execution (4), Initial Access (4), Resource Development (4), Collection (3)
  • T1059.006 Python — Executionobserved in 2 of 2 tracked threats
  • T1110.003 Password Spraying — Credential Accessobserved in 2 of 2 tracked threats
  • T1114.002 Email Collection: Remote Email Collection — Collectionobserved in 2 of 2 tracked threats
  • T1133 External Remote Services — Persistenceobserved in 2 of 2 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
  • T1505.003 Server Software Component: Web Shell — Persistenceobserved in 2 of 2 tracked threats
  • T1566 Phishing — Initial Accessobserved in 2 of 2 tracked threats
  • T1572 Protocol Tunneling — Command and Controlobserved in 2 of 2 tracked threats
  • T1583.001 Domains — Resource Developmentobserved in 2 of 2 tracked threats
  • T1584.005 Compromise Infrastructure: Botnet — Resource Developmentobserved in 2 of 2 tracked threats
  • T1595.002 Active Scanning: Vulnerability Scanning — Reconnaissanceobserved in 2 of 2 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 1 of 2 tracked threats
  • T1003.001 LSASS Memory — Credential Accessobserved in 1 of 2 tracked threats
  • T1003.006 OS Credential Dumping: DCSync — Credential Accessobserved in 1 of 2 tracked threats
  • T1020 Automated Exfiltration — Exfiltrationobserved in 1 of 2 tracked threats

Tracked threats

Related CVEs

9 CVEs referenced by tracked Flax Typhoon activity