VORANT. Threat Intelligence Sign in Get the full feed

FBI Unmasks Flax Typhoon as Integrity Technology Group

high threat government-nationalmediaeducationinfrastructureenergy

FBI-led operation dismantled a Flax Typhoon botnet of hijacked IoT devices and revealed the Chinese state-linked group is actually Integrity Technology Group.

FBI Director Christopher Wray announced at the Aspen Cyber Summit that a joint law enforcement operation disrupted a botnet run by Flax Typhoon, a Chinese government-sponsored hacking group. The botnet compromised thousands of internet-connected devices—including storage devices, IP cameras, and video recorders—roughly half of them in the United States, to steal confidential data from public and private sector organizations, academia, and media outlets. With court authorization, the FBI issued remote removal commands to strip malware from infected devices, though Wray characterized the takedown as only one round in an ongoing conflict with Chinese state-sponsored cyber activity.

Significantly, Wray publicly attributed Flax Typhoon's operations to Integrity Technology Group, an ostensibly private information security firm whose chairman has reportedly admitted to conducting intelligence collection and reconnaissance on behalf of Chinese government security agencies. This exposure represents a notable unmasking of a nation-state proxy relationship. Wray also referenced a separate, unrelated joint advisory warning that a pro-Russian hacktivist group had been targeting operational technology networks across dams, wastewater systems, energy, and food/agriculture sectors, which allowed private sector organizations to remediate the exploited vulnerability before further compromise.

The remainder of the remarks focused on the FBI's broader cyber engagement strategy, including its ransomware decryptor program (nearly 1,000 decryptors issued and roughly $800 million in ransom payments saved over two years) and the importance of victim reporting to enable decryption key matching and recovery support.

Mentioned in this report

Threat actors Flax Typhoon
Malware Flax Typhoon botnet malware

Source reporting: https://www.fbi.gov/news/stories/fbi-director-announces-chinese-botnet-disruption-exposes-flax-typhoon-hacker-group-s-true-identity-at-aspen-cyber-summit

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free