China's Flax Typhoon Hackers Target Taiwan, Microsoft Warns

Microsoft has identified a new hacking group called Flax Typhoon that primarily targets government agencies, education, critical manufacturing, and IT organizations for espionage purposes. Flax Typhoon relies on living-off-the-land binaries (LOLBins) and legitimate software rather than malware to gain and maintain access to victim networks. The group exploits known vulnerabilities in public-facing servers, drops web shells, elevates privileges, establishes persistence, and uses VPN bridges to maintain connections. They also utilize LOLBins for lateral movement and extract credentials using tools like Mimikatz. Microsoft advises organizations to apply security updates, enable multi-factor authentication, and monitor registry changes to protect against Flax Typhoon.
- Microsoft: Stealthy Flax Typhoon hackers use LOLBins to evade detection BleepingComputer
- China Unleashes Flax Typhoon APT to Live Off the Land, Microsoft Warns DARKReading
- Microsoft says Chinese hacking crew is targeting Taiwan CyberScoop
- China-Linked Flax Typhoon Cyber Espionage Targets Taiwan's Key Sectors The Hacker News
- Microsoft says Chinese group has hacked into Taiwan networks Taiwan News
- View Full Coverage on Google News
Reading Insights
1
10
2 min
vs 3 min read
80%
500 → 100 words
Want the full story? Read the original article
Read on BleepingComputer