What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft said on August 24, 2023, that a China-based group it calls Flax Typhoon had targeted dozens of organizations in Taiwan. The company assessed the campaign as likely intended for espionage, but said it had not observed the group act on its final objectives. Its disclosure describes how the intruders sought to keep long-term access—not confirmed data theft or completed espionage.

Who is Flax Typhoon?

Flax Typhoon is the name Microsoft uses for a China-based nation-state activity group. Microsoft said the group had been active since mid-2021. That attribution and activity timeline are Microsoft’s assessment, not a claim that every technical detail has been independently confirmed. Microsoft’s August 24, 2023 disclosure is the primary account.

Which organizations did Microsoft say were targeted?

In its account of the Taiwan campaign, Microsoft identified organizations in government, education, critical manufacturing, and information technology. It also reported victims in Southeast Asia, North America, and Africa, without naming individual organizations.

A separate, broader Microsoft assessment of East Asia described Flax Typhoon as the most prominent group targeting Taiwan and listed telecommunications, education, information technology, and energy infrastructure among its primary targets. That wider sector list is a regional assessment, not a replacement for the Taiwan campaign account. Both reports date to 2023; they do not establish the group’s current activity in 2026. Microsoft’s broader East Asia assessment provides that context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did the group maintain access?

Microsoft described a combination of exploited internet-facing systems and tools already available on Windows computers. The company said Flax Typhoon primarily relied on “living-off-the-land” techniques—using legitimate system utilities and other software already present—and hands-on-keyboard activity. The sequence and methods below summarize Microsoft’s report; they should not be read as independently verified details of every intrusion.

Initial access and privilege escalation

Microsoft said the group exploited known vulnerabilities in public-facing VPN, web, Java, and SQL applications. It reported use of web shells, including China Chopper, to enable remote execution. In some cases, it said the actors used privilege-escalation tools such as Juicy Potato and BadPotato.

Persistence and movement through networks

For persistence, Microsoft described use of Windows command-line tools and Remote Desktop Protocol (RDP), changes that disabled Network Level Authentication, abuse of the Sticky Keys sign-in shortcut, and VPN connections to infrastructure controlled by the actors. The company said the group focused on persistence, lateral movement, and credential access.

Did Microsoft confirm data theft or completed espionage?

No. Microsoft assessed that the activity was likely intended for espionage and described the actor as seeking long-term access, but it said it had not observed the group act on final objectives in this campaign. As Microsoft put it: “Microsoft has not observed Flax Typhoon using this access to conduct additional actions.” The disclosure therefore does not establish that data was stolen or that espionage was completed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What did Microsoft recommend for defenders?

Microsoft’s general recommendations were to address vulnerabilities on systems and services exposed to the public internet, harden systems against credential access, and investigate suspected compromises. Its guidance also called for assessing the scale of activity, closing or changing compromised accounts, isolating and investigating affected systems, removing malicious tools, and checking logs for compromised accounts. These are defensive steps, not a guarantee that an organization will prevent or fully remediate an intrusion. Microsoft said it had directly notified targeted or compromised customers and explained that it published the account partly because of potential downstream customer impact and limited visibility into other parts of the group’s activity. The Record’s contemporary coverage also reported on the disclosure.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.