Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Flax Typhoon

🇨🇳Flax Typhoon

🇨🇳 Flax Typhoon is a tracked threat actor in the Clankerusecase corpus. Attributed to CN. Primary motivation: State. We map 11 detection use cases to this actor across 18 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2025-11-06 to 2025-11-06.

crit 1
View full actor card → All threat actors
11Use cases
1Articles
18Techniques
0IOCs

Known aliases

Flax TyphoonEthereal Panda

Top techniques

All other tracked techniques

Detection use cases (11)

Flax Typhoon Sticky Keys / Accessibility Feature debugger hijack via IFEO registry AI · profile SΣ Flax Typhoon SoftEther VPN bridge persistence (vpnbridge / vpnserver / vpnclient) AI · profile S Archive utility writing LNK/DLL/EXE to Windows Startup folder (RomCom CVE-2025-8088) Bespoke Python interpreter executed from %TEMP% / Public — RomCom DLL side-load chain (CVE-2025-8088) Bespoke Asset exposure — vulnerability matches article CVE(s) Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Remote service execution — PsExec / SMB lateral movement Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal

Threat-intel articles (1)

Tracked indicators

CVEs (2)

CVE-2024-42009 CVE-2025-8088