TT Malware Log

マルウェア / サイバー攻撃 / 解析技術 / 攻撃組織 / 攻撃技術 に関する「個人」の調査・研究

Flax Typhoon (まとめ)

【要点】

◎台湾の組織を主な標的にする、中国政府が支援する攻撃組織
◎ネットワークへの長期的なアクセス権を取得し維持することに重点を置いている
◎LotLを使用して、検出を回避


malware-log.hatenablog.com


【別名】

攻撃組織名
命名組織・備考
Ethereal Panda Crowdstrike
Flax Typhoon Microsoft
Integrity Technology Group Flax Typhoon をコントロールする上部組織
Red Juliet Insikt Group
Storm-0919 Microsoft (旧名称)
UNC5007 Mandiant


【辞書】

◆Flax Typhoon (Malpedia)
https://malpedia.caad.fkie.fraunhofer.de/actor/flax_typhoon


【ニュース】

■2023年

◇2023年8月

◆ネットワークに長期間潜む中国の脅威グループFlax Typhoon、Microsoft警告 (マイナビニュース, 2023/08/29 09:26)
https://news.mynavi.jp/techplus/article/20230829-2759424/
https://malware-log.hatenablog.com/entry/2023/08/29/000000


■2024年

◇2024年9月

◆TP-LINK製ルータなど数十万台のデバイスの侵害発見、サイバー攻撃の兆候か (マイナビニュース, 2024/09/20 09:10)
https://news.mynavi.jp/techplus/article/20240920-3028236/
https://malware-log.hatenablog.com/entry/2024/09/20/000000_5


■2025年

◇2025年1月

◆US sanctions Chinese company linked to Flax Typhoon hackers (BleepingComputer, 2025/01/03 11:19)
[米国、Flax Typhoonハッカーとつながりのある中国企業に制裁]
https://www.bleepingcomputer.com/news/security/us-sanctions-chinese-company-linked-to-flax-typhoon-hackers/
https://malware-log.hatenablog.com/entry/2025/01/03/000000

◆US Sanctions Chinese Firm Linked to Flax Typhoon Attacks on Critical Infrastructure (SecurityWeek, 2025/01/06)
[米国、重要インフラへのサイバー攻撃に関与した中国企業に制裁措置]

The US Treasury has sanctioned Chinese company Integrity Technology for supporting state-sponsored group Flax Typhoon in hacking US critical infrastructure.
[米国財務省は、中国政府支援のハッカー集団Flax Typhoonによる米国の重要インフラへのハッキングを支援したとして、中国企業インテグリティー・テクノロジー社に制裁措置を科した]

https://www.securityweek.com/us-sanctions-chinese-firm-linked-to-flax-typhoon-attacks-on-critical-infrastructure/
https://malware-log.hatenablog.com/entry/2025/01/06/000000_2

◆中国の「Typhoon」ハッカーグループ:Volt Typhoon、Flax Typhoon、Salt Typhoonの概要や注目ポイント (Codebook, 2025/01/07)
https://codebook.machinarecord.com/threatreport/36791/
https://malware-log.hatenablog.com/entry/2025/01/07/000000_4


◇2025年10月

◆中国のAPTグループがArcGISをバックドア化、検出を1年間以上回避 (codebook, 2025/10/14)
https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/41421/
https://malware-log.hatenablog.com/entry/2025/10/14/000000_2

◆McCrary report flags China’s escalating cyber tactics, warns of Typhoon cyber threats to US critical infrastructure (Indistrial Cyber, 2025/10/30)
[マクラリー報告書は中国のエスカレートするサイバー戦術を指摘し、米国の重要インフラに対する台風サイバー脅威を警告]
https://industrialcyber.co/reports/mccrary-report-flags-chinas-escalating-cyber-tactics-warns-of-typhoon-cyber-threats-to-us-critical-infrastructure/
https://malware-log.hatenablog.com/entry/2025/10/30/000000


【ブログ】

■2024年

◇2024年9月

◆Derailing the Raptor Train (Lumen, 2024/09/18)
[Raptor Train の脱線]
https://blog.lumen.com/derailing-the-raptor-train/
https://malware-log.hatenablog.com/entry/2024/09/18/000000_8


【公開情報】

■2026年

◇2026年4月

◆侵害されたデバイスで構成される中国関連の匿名ネットワーク に対する防御に関するアドバイザリーへの共同署名について (NCO, 2026/04/23)
https://www.cyber.go.jp/pdf/press/Defending_against_China_linked_covert_networks_of_compromised_devices.pdf
https://malware-log.hatenablog.com/entry/2026/04/23/000000_18


【検索】

■Google

google: Flax Typhoon
google:news: Flax Typhoon
google: site:virustotal.com Flax Typhoon
google: site:github.com Flax Typhoon


■Bing

https://www.bing.com/search?q=Flax%20Typhoon
https://www.bing.com/news/search?q=Flax%20Typhoon


■Twitter

https://twitter.com/search?q=%23Flax%20Typhoon
https://twitter.com/hashtag/Flax%20Typhoon


【関連まとめ記事】

全体まとめ
 ◆攻撃組織 / Actor (まとめ)

◆標的型攻撃組織 / APT (まとめ)
https://malware-log.hatenablog.com/entry/APT


Copyright (C) 谷川哲司 (Tetsuji Tanigawa) 1997 - 2023