A patching deadline set by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) arrives today, October 11, capping a week of escalating action against Flax Typhoon — the Chinese state-sponsored threat group that seven governments now accuse of systematically infiltrating critical infrastructure worldwide. If your organization runs ProFTPD, Apache Struts, ONLYOFFICE Docs, Strapi, or ISC BIND, this one demands your attention.
What Happened
On October 9, CISA added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, each confirmed to be actively exploited by Flax Typhoon — a group also tracked as Ethereal Panda and Red Juliett. Under Binding Operational Directive 22-01, all federal civilian agencies must either patch the affected software or stop using it by October 11, 2026.
The move came alongside a joint advisory (AA26-281A) co-signed by cybersecurity agencies from Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States. The advisory directly attributes the campaign to Integrity Technology Group, a Beijing-based cybersecurity contractor alleged to have Chinese government contracts and to have built the tools Flax Typhoon uses in the field.
A day earlier, on October 8, the FBI and the Department of Justice announced the seizure of seven domains tied to two of those tools: MicroScan, a vulnerability scanner accessed through the domain c0cc[.]cc, and FishHub, a post-compromise spearphishing and file-harvesting platform distributed through five additional domains.
The Five Flaws
The vulnerabilities are a mix of old and relatively recent, but all remain exploitable in environments that have not applied patches — some dating back more than a decade:
CVE-2015-3306 (CVSS 10.0) — ProFTPD 1.3.5: An improper access control flaw that lets unauthenticated remote attackers read and write arbitrary files using the SITE CPFR and SITE CPTO commands. Flax Typhoon has used it to steal configuration files containing database credentials and SSH keys. Organizations should upgrade to ProFTPD 1.3.7 or later.
CVE-2021-3199 (CVSS 9.8) — ONLYOFFICE Docs: A path-traversal vulnerability when JSON Web Token authentication is enabled. An attacker can escape the document server root through a crafted image upload parameter, potentially achieving remote code execution.
CVE-2016-3081 (CVSS 8.1) — Apache Struts 2.x: A command injection flaw via the \”method:\” prefix when Dynamic Method Invocation (DMI) is enabled. It allows remote code execution. Administrators should disable DMI or upgrade to Struts 2.3.33 or later.
CVE-2023-22894 (CVSS 7.2) — Strapi: Sensitive user information stored in cleartext can be exposed when an authenticated admin crafts a specific query filter. While the CVSS score is lower, the credential exposure it enables can serve as a stepping stone for deeper compromise.
CVE-2015-5477 (CVSS 7.5) — ISC BIND 9.x: A reachable assertion triggered by crafted TKEY queries that causes denial of service. Upgrade to BIND 9.9.7-P2 or later to remediate.
Three additional vulnerabilities — Shellshock in GNU Bash (CVE-2014-6278), an arbitrary file read in Ivanti Pulse Connect Secure (CVE-2019-11510), and a remote code execution flaw in GitLab (CVE-2021-22205) — were already in the KEV catalog from earlier additions and are also part of this campaign, bringing the total to eight exploited flaws.
How Flax Typhoon Operates
The joint advisory outlines a methodical attack chain. Reconnaissance begins with MicroScan, the vulnerability scanner whose infrastructure the FBI seized, which scans internet-facing hosts and maps services to the known CVEs. Initial access is achieved by exploiting the eight vulnerabilities and through FishHub spearphishing campaigns that impersonate LinkedIn and Outlook notifications.
Once inside, the group establishes persistence using China Chopper web shells and SoftEther VPN software. Credential theft follows, with EBurst password spraying against Microsoft Exchange servers and Mimikatz-based LSASS memory dumping. The final stage involves bulk mailbox export through Exchange APIs, with exfiltrated data relayed through the group’s Raptor Train botnet — a network of over 200,000 compromised IoT devices, including routers, DVRs, NAS appliances, and cameras.
Court documents unsealed alongside the domain seizures allege that MicroScan was previously used to probe targets including a South Carolina electric utility, a multinational NGO, airports in Japan and Poland, and Taiwanese energy companies. FishHub reportedly infected around 20 Taiwanese universities and was still active as recently as March 2026.
Who Is at Risk
The advisory names confirmed targeting across U.S. and allied government agencies, critical manufacturing, healthcare, IT service providers, law enforcement, education, and religious organizations. Geographically, the campaign has hit targets in the United States, Taiwan, Southeast Asia (Vietnam, Malaysia, Thailand, the Philippines), parts of Africa, and beyond.
But the underlying vulnerabilities are not limited to these sectors. Any organization running an unpatched instance of ProFTPD, Struts, BIND, ONLYOFFICE Docs, or Strapi is potentially exposed — whether or not it fits the profile of a typical nation-state target. Opportunistic exploitation of known CVEs does not discriminate by industry.
The Bigger Picture
This is not the first time Flax Typhoon’s infrastructure has been disrupted. In September 2024, the FBI dismantled an earlier generation of the Raptor Train botnet, which at the time comprised roughly 260,000 compromised devices. In August 2026, authorities disrupted a separate botnet and seized domains tied to platforms allegedly used to target NASA, the U.S. Senate, and the Department of Energy.
CISA’s Chris Butera, acting executive assistant director for cybersecurity, framed the threat bluntly: \”Chinese government-affiliated actors continue to position themselves within critical infrastructure networks,\” including operational technology systems, \”to disrupt critical functions at a future time of their choosing.\”
The pattern — old vulnerabilities, persistent access, and pre-positioned disruption capability — mirrors the broader Volt Typhoon campaign that drew widespread attention in 2024 and 2025, signaling that Chinese cyber operations against Western infrastructure remain a top-tier strategic concern.
What You Should Do Now
Today’s deadline applies directly to federal agencies, but every organization should treat it as a signal to act. Start by checking whether you run any of the five affected products and verify patch levels. Upgrade ProFTPD to 1.3.7+, disable Dynamic Method Invocation in Struts or upgrade to 2.3.33+, and update BIND to 9.9.7-P2 or later. For ONLYOFFICE and Strapi, apply the latest available patches from the respective vendors.
Beyond patching, the advisory recommends blocking the seized domains and known command-and-control infrastructure, monitoring for indicators of SoftEther VPN silent installation, implementing phishing-resistant multi-factor authentication, and reviewing Exchange authentication logs for password-spray patterns — specifically, more than five failed login attempts from a single IP within five minutes.
The seven-nation advisory, the FBI domain seizures, and the KEV deadline all landing within 72 hours of each other is not coincidence — it is coordinated pressure. The message is clear: patch now, or become the next case study in how old vulnerabilities enable new intrusions.
Leave a Reply