PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Feds Sanction Chinese Firm for Helping 'Flax Typhoon' Hackers

The Treasury Department says Integrity Tech operated Flax Typhoon's botnet—a network of at least 260,000 compromised devices that helped the attackers hide their identities.

 & Kate Irwin Reporter

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS
(Credit: Nikada/E+ via Getty Images)

The US Treasury Department has sanctioned Chinese firm Integrity Technology Group for allegedly supporting the Chinese hacker group "Flax Typhoon."

"Between summer 2022 and fall 2023, Flax Typhoon actors used infrastructure tied to Integrity Tech during their computer network exploitation activities against multiple victims. During that time, Flax Typhoon routinely sent and received information from Integrity Tech infrastructure," the Treasury Department says.

The sanctions mean that any US companies or people with ties to Integrity Tech are expected to report any assets or dealings to the Treasury Department's Office of Foreign Assets Control (OFAC). Financial intermediaries are also expected to stop doing business with or for the firm.

US authorities believe Flax Typhoon has operated since at least 2021 and has pursued a range of global targets, including US entities. The group often attacks critical infrastructure and previously breached "multiple servers and workstations" at an "entity" in California, Treasury said without elaborating. Group affiliates typically use VPN software and remote-access software to gain and retain access to breached systems. In 2023, Microsoft said Flax Typhoon had targeted Taiwan organizations for Chinese espionage purposes.

In September, international authorities—including those in the US, Canada, and Australia—co-published an 18-page report detailing how Chinese state-affiliated cybercriminals are attacking routers and devices abroad using botnets to deploy malware or conduct DDoS attacks. They found that Integrity Tech operated Flax Typhoon's botnet—a network of what may be at least 260,000 compromised devices that helped the attackers hide their identities.

"Integrity Tech has used China Unicom Beijing Province Network IP addresses to control and manage the botnet described in this advisory," the report on the firm's ties to Flax Typhoon reads, adding: "FBI has engaged with multiple US victims of these computer intrusions and found activity consistent with the tactics, techniques, and infrastructure associated with the cyber threat group known publicly as Flax Typhoon, RedJuliett, and Ethereal Panda."

These sanctions come just days after Chinese hackers reportedly breached computers belonging to OFAC—which itself establishes sanctions—and viewed unclassified documents. The Treasury did not specify whether it believes Flax Typhoon or a different hacker group conducted that attack (The New York Times reports that one of China's intelligence agencies conducted the breach. It also said this attack was to gain intel, not to brick OFAC computer systems).

A different Chinese hacker group, Salt Typhoon, has been blamed for breaching at least nine different US telecommunications firms, including AT&T and Verizon, by using existing software flaws. On Monday, those two wireless giants both said they no longer detected any Salt Typhoon presence on their networks.

About Our Expert

Kate Irwin

Kate Irwin

Reporter

I’m a reporter for PCMag covering tech news early in the morning. Prior to joining PCMag, I was a producer and reporter at Decrypt and launched its gaming vertical, GG. I have previously written for Input, Game Rant, Dot Esports, and other places, covering a range of gaming, tech, crypto, and entertainment news.

I’ve been a PC gamer since The Sims (yes, the original) in the CD-ROM days. I still think about my first-gen pink iPod mini, which, looking back, was not so mini. In 2020, I finally built my own custom Windows PC for gaming with a 3090 graphics card, but I also regularly use Mac and iOS devices. As a reporter, I’m passionate about documenting the wide world of tech and how it affects our daily lives.

My Areas of Expertise

  • Microsoft
  • Google
  • Artificial intelligence 
  • Cybersecurity
  • Video games are a big one. I specialize in shooters (Apex Legends, Fortnite, Overwatch) but I occasionally test out other genres as well, especially indie games or cozy games (The Sims series, Animal Crossing). 
  • The business and tech that powers video games
  • Cryptocurrency and blockchain technology
  • Social media platforms, including Meta’s apps, X/Twitter, Telegram, TikTok, etc.
  • Tech regulation

The Technology I Use

  • MSI gaming laptops
  • Nvidia graphics cards
  • AMD CPUs
  • MacBook Pro and Air laptops
  • An iPhone from 2019 (though I’m thinking about getting a “dumb phone” like the Light Phone)
  • Nintendo Switch
  • PlayStation 5
  • Freewrite Traveler 
  • At home: Sonos speakers (we have them all over the house), Philips Hue + Ring security products

Read full bio