[threat-actors] Add Flax Typhoon

This commit is contained in:
Mathieu4141 2024-01-22 10:01:13 -08:00
parent 3f9bd89958
commit bd7252ccef

View file

@ -14047,6 +14047,21 @@
},
"uuid": "6c706d8b-95a4-428d-9de5-b68b29b1893c",
"value": "TAG-28"
},
{
"description": "Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan. They conduct espionage campaigns and focus on gaining and maintaining long-term access to networks using minimal malware. Flax Typhoon relies on tools built into the operating system and legitimate software to remain undetected. They exploit vulnerabilities in public-facing servers, use living-off-the-land techniques, and deploy a VPN connection to maintain persistence and move laterally within compromised networks.",
"meta": {
"country": "CN",
"refs": [
"https://www.microsoft.com/en-us/security/blog/2023/08/24/flax-typhoon-using-legitimate-software-to-quietly-access-taiwanese-organizations/",
"https://www.crowdstrike.com/global-threat-report/"
],
"synonyms": [
"Ethereal Panda"
]
},
"uuid": "50ee2b1b-979e-4507-8747-8597a95938f6",
"value": "Flax Typhoon"
}
],
"version": 297