
China's Flax Typhoon Hackers Target Taiwan, Microsoft Warns
Microsoft has identified a new hacking group called Flax Typhoon that primarily targets government agencies, education, critical manufacturing, and IT organizations for espionage purposes. Flax Typhoon relies on living-off-the-land binaries (LOLBins) and legitimate software rather than malware to gain and maintain access to victim networks. The group exploits known vulnerabilities in public-facing servers, drops web shells, elevates privileges, establishes persistence, and uses VPN bridges to maintain connections. They also utilize LOLBins for lateral movement and extract credentials using tools like Mimikatz. Microsoft advises organizations to apply security updates, enable multi-factor authentication, and monitor registry changes to protect against Flax Typhoon.