Full Report
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) on Friday issued sanctions against a Beijing-based cybersecurity company known as Integrity Technology Group, Incorporated for orchestrating several cyber attacks against U.S. victims. These attacks have been publicly attributed to a Chinese state-sponsored threat actor tracked as Flax Typhoon (aka Ethereal Panda or
Analysis Summary
# Threat Actor: Flax Typhoon (Attributed to China State-Sponsored Activities)
## Attribution & Identity
* **Primary Identified Entity Sanctioned:** Integrity Technology Group, Incorporated (also known as Yongxin Zhicheng).
* **Attribution:** Directly linked to a Chinese state-sponsored threat actor.
* **Known Aliases:** Ethereal Panda, RedJuliett.
* **Known Associations:** Integrity Technology Group is classified as a government contractor with ties to the People's Republic of China (PRC) Ministry of State Security (MSS). It provides services to State Security and Public Security Bureaus.
## Activity Summary
* The U.S. Treasury Department issued sanctions against Integrity Technology Group for orchestrating cyber attacks publicly attributed to Flax Typhoon.
* The group has been active since at least mid-2021.
* Flax Typhoon has been operating an Internet of Things (IoT) botnet known as Raptor Train.
* The Treasury Department views this actor as one of the "most active and most persistent threats to U.S. national security."
* Integrity Group allegedly provided infrastructure support to Flax Typhoon campaigns between mid-2022 and late-2023.
## Tactics, Techniques & Procedures
* **Initial Access:** Typically leverages known vulnerabilities to gain initial access to victims' computers.
* **Persistence:** Makes use of legitimate, living-off-the-land, remote access software to maintain persistent access.
* **Infrastructure:** Utilized the Raptor Train IoT botnet.
## Targeting
* **Sectors:** Explicitly mentioned targeting U.S. government systems, but also targeting various entities across different sectors.
* **Geography:** North America, Europe, Africa, and Asia.
* **Victims:** U.S. government systems; various entities across global regions.
## Tools & Infrastructure
* **Malware Families Used:** Raptor Train (IoT Botnet).
* **Infrastructure (C2, domains, IPs):** Infrastructure support provided by Integrity Technology Group (Yongxin Zhicheng). (No specific URLs or IPs detailed in the provided text).
## Implications
The sanctions against the enabling entity (Integrity Group) indicate a U.S. government determination to hold accountable commercial entities that provide support (infrastructure and services) to state-sponsored espionage campaigns like Flax Typhoon. This actor remains a persistent and high-priority threat to U.S. national security systems.
## Mitigations
* Harden public and private sector cyber defenses collaboratively.
* Implement measures to quickly identify and mitigate exploitation of known vulnerabilities for initial access.
* Monitor for the use of legitimate remote access software indicative of persistent unauthorized presence.