FBI Disrupts Flax Typhoon Tools Targeting U.S. Critical Infrastructure
Agencies seize seven domains linked to China-affiliated APT group; scanning and infiltration capabilities blocked

Key Takeaways
- FBI and DoJ seized seven domains linked to Flax Typhoon, a China-affiliated APT group.
- The domains were used for reconnaissance scanning and initial access to critical infrastructure.
- The operation disrupted Flax Typhoon's reconnaissance and infiltration capabilities.
- Organizations are advised to review logs for Flax Typhoon indicators of compromise.
Related Security News

CISA Adds Five Vulnerabilities to KEV Catalog Following Flax Typhoon Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation by the China-linked threat actor Flax Typhoon. The newly listed vulnerabilities include CVE-2015-3306 in ProFTPD and four Windows components: CVE-2025-21335 (MSHTML), CVE-2025-21333 (Win32k), CVE-2025-21334 (HTTP Protocol Stack), and CVE-2025-21336 (Kernel). Federal agencies must patch all listed vulnerabilities by October 11, 2026.



