threatintel
actor tracker
Flax Typhoon
Sanctionseverity: High2024-09-18

FBI disrupts 260,000-device Flax Typhoon IoT botnet

published by U.S. Federal Bureau of Investigation
Actor
Flax TyphoonCN · ChinaAPT

PRC state-affiliated intrusion set operating through Integrity Technology Group — a Beijing-based, publicly-traded cybersecurity contractor sanctioned by the U.S. Treasury OFAC in January 2025. Speci…

Summary

FBI Director Christopher Wray announced at the Aspen Cyber Summit that the FBI and partners had disrupted a botnet of 260,000+ compromised IoT devices (routers, IP cameras, NVRs, storage devices) operated by PRC-affiliated Flax Typhoon, identified as operating through Integrity Technology Group — a Beijing-based publicly-traded cybersecurity contractor. Of the compromised devices, approximately half were in the United States. Treasury OFAC subsequently sanctioned Integrity Technology Group in January 2025.

Tags

botnettakedowniotchina

Primary source

fbi.gov