Threat Actor
Flax Typhoon
- First Reported
- Oct 8, 2026
- Latest Reported
- Oct 9, 2026
Reported Context (3)
- Named campaign in which Rob Joyce testified that TP-Link routers were among the brands exploited; TP-Link disputed the claim. Four More U.S. States Sue TP-Link Over Router Security and China Ties
- Identified as a China-linked threat actor whose abuse of five security flaws preceded their addition to CISA's KEV catalog. CISA Adds Five Flax Typhoon-Exploited Flaws to KEV, Sets October 11 Federal Deadline
- Chinese state-sponsored hacking group identified as using the seized infrastructure. The joint advisory describes overlapping activity tracked under this name, while cautioning that not all activity is necessarily linked to Integrity Tech. FBI Seizes Domains Used by China-Linked Hackers to Target Critical Infrastructure
CVE (10)
Malware (2)
People (7)
Threat Actors (5)
MITRE ATT&CK (6)
Vendors (2)
Products (30)
Tools (3)
Industries (8)
Countries (7)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.