# Flax Typhoon

> As of 2026-10-09, Flax Typhoon is a China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning apt. Also known as Integrity Technology Group. ATT&CK coverage spans 32 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1059.006 (Python), T1110.003 (Password Spraying), T1114.002 (Email Collection: Remote Email Collection).

- **Nation:** China
- **Tracked threats:** 2
- **Categories:** APT
- **Also known as:** Integrity Technology Group
- **As of:** 2026-10-09

## ATT&CK techniques observed

32 techniques observed across 2 of 2 tracked threats. Tactics: Credential Access (5), Command and Control (4), Execution (4), Initial Access (4), Resource Development (4), Collection (3).

- [T1059.006](https://intel.threadlinqs.com/technique/T1059.006) Python — Execution — observed in 2 of 2 tracked threats
- [T1110.003](https://intel.threadlinqs.com/technique/T1110.003) Password Spraying — Credential Access — observed in 2 of 2 tracked threats
- [T1114.002](https://intel.threadlinqs.com/technique/T1114.002) Email Collection: Remote Email Collection — Collection — observed in 2 of 2 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Persistence — observed in 2 of 2 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 2 of 2 tracked threats
- [T1505.003](https://intel.threadlinqs.com/technique/T1505.003) Server Software Component: Web Shell — Persistence — observed in 2 of 2 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 2 of 2 tracked threats
- [T1572](https://intel.threadlinqs.com/technique/T1572) Protocol Tunneling — Command and Control — observed in 2 of 2 tracked threats
- [T1583.001](https://intel.threadlinqs.com/technique/T1583.001) Domains — Resource Development — observed in 2 of 2 tracked threats
- [T1584.005](https://intel.threadlinqs.com/technique/T1584.005) Compromise Infrastructure: Botnet — Resource Development — observed in 2 of 2 tracked threats
- [T1595.002](https://intel.threadlinqs.com/technique/T1595.002) Active Scanning: Vulnerability Scanning — Reconnaissance — observed in 2 of 2 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 1 of 2 tracked threats
- [T1003.001](https://intel.threadlinqs.com/technique/T1003.001) LSASS Memory — Credential Access — observed in 1 of 2 tracked threats
- [T1003.006](https://intel.threadlinqs.com/technique/T1003.006) OS Credential Dumping: DCSync — Credential Access — observed in 1 of 2 tracked threats
- [T1020](https://intel.threadlinqs.com/technique/T1020) Automated Exfiltration — Exfiltration — observed in 1 of 2 tracked threats

## Tracked threats

- [FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub Spear-Phishing Infrastructure Operated by China-Based Integrity Technology Group (Flax Typhoon-linked)](https://intel.threadlinqs.com/threat/TL-2026-3077) — HIGH
- [Chinese Government-linked Actors Enabled by Integrity Technology Group Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (CISA AA26-281A)](https://intel.threadlinqs.com/threat/TL-2026-3054) — HIGH

## Related CVEs

9 CVEs referenced by tracked Flax Typhoon activity.

- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2023-22894](https://intel.threadlinqs.com/cve/CVE-2023-22894)
- [CVE-2021-3199](https://intel.threadlinqs.com/cve/CVE-2021-3199)
- [CVE-2021-22205](https://intel.threadlinqs.com/cve/CVE-2021-22205)
- [CVE-2019-11510](https://intel.threadlinqs.com/cve/CVE-2019-11510)
- [CVE-2016-3081](https://intel.threadlinqs.com/cve/CVE-2016-3081)
- [CVE-2015-5477](https://intel.threadlinqs.com/cve/CVE-2015-5477)
- [CVE-2015-3306](https://intel.threadlinqs.com/cve/CVE-2015-3306)
- [CVE-2014-6278](https://intel.threadlinqs.com/cve/CVE-2014-6278)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Flax%20Typhoon
