China's Flax Typhoon Hackers Target Taiwan, Microsoft Warns

1 min read
Source: BleepingComputer
China's Flax Typhoon Hackers Target Taiwan, Microsoft Warns
Photo: BleepingComputer
TL;DR Summary

Microsoft has identified a new hacking group called Flax Typhoon that primarily targets government agencies, education, critical manufacturing, and IT organizations for espionage purposes. Flax Typhoon relies on living-off-the-land binaries (LOLBins) and legitimate software rather than malware to gain and maintain access to victim networks. The group exploits known vulnerabilities in public-facing servers, drops web shells, elevates privileges, establishes persistence, and uses VPN bridges to maintain connections. They also utilize LOLBins for lateral movement and extract credentials using tools like Mimikatz. Microsoft advises organizations to apply security updates, enable multi-factor authentication, and monitor registry changes to protect against Flax Typhoon.

Share this article

Reading Insights

Total Reads

1

Unique Readers

10

Time Saved

2 min

vs 3 min read

Condensed

80%

500100 words

Want the full story? Read the original article

Read on BleepingComputer