Activity timeline
Flax Typhoon appears in 2 tracked threats between and .
ATT&CK techniques observed
- T1059.006 Python — Executionobserved in 2 of 2 tracked threats
- T1110.003 Password Spraying — Credential Accessobserved in 2 of 2 tracked threats
- T1114.002 Email Collection: Remote Email Collection — Collectionobserved in 2 of 2 tracked threats
- T1133 External Remote Services — Persistenceobserved in 2 of 2 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
- T1505.003 Server Software Component: Web Shell — Persistenceobserved in 2 of 2 tracked threats
- T1566 Phishing — Initial Accessobserved in 2 of 2 tracked threats
- T1572 Protocol Tunneling — Command and Controlobserved in 2 of 2 tracked threats
- T1583.001 Domains — Resource Developmentobserved in 2 of 2 tracked threats
- T1584.005 Compromise Infrastructure: Botnet — Resource Developmentobserved in 2 of 2 tracked threats
- T1595.002 Active Scanning: Vulnerability Scanning — Reconnaissanceobserved in 2 of 2 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 1 of 2 tracked threats
- T1003.001 LSASS Memory — Credential Accessobserved in 1 of 2 tracked threats
- T1003.006 OS Credential Dumping: DCSync — Credential Accessobserved in 1 of 2 tracked threats
- T1020 Automated Exfiltration — Exfiltrationobserved in 1 of 2 tracked threats
Tracked threats
- FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub Spear-Phishing Infrastructure Operated by China-Based Integrity Technology Group (Flax Typhoon-linked)HIGH
- Chinese Government-linked Actors Enabled by Integrity Technology Group Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (CISA AA26-281A)HIGH