The Flax Typhoon Advisory Lists 514 IP Addresses. Two Were Seen After 2024. We Checked What Still Answers.
Yesterday ten agencies across seven countries published a joint advisory, AA26-281A, on Integrity Technology Group, the China-based company the authors say builds tools, rents infrastructure and breaks into networks for Chinese government-linked hackers. Private-sector researchers know the activity as Flax Typhoon, Ethereal Panda and Red Juliett. The advisory ships 773 indicators of compromise in a machine-readable file, and on page 19 it says something most people will skip: several of these indicators date back to 2016, and you should vet them before you block them.
So we vetted them. This post is what that looks like, what we put into our feed, and what we deliberately left out.
!773 indicators from ten agencies: what still answers today. Of 514 IP addresses, 164 were last seen between 2019 and 2022, 175 in 2023, 173 in 2024, 2 in 2025 and none in 2026. 156 geolocate to residential lines in Xiamen, China; 99 are rented Vultr servers; 85 are in Taiwan, 80 of them on home connections that look like hijacked relay nodes. Of 218 domain names, 69 still resolve on October 9, 23 to a real server rather than a CDN, parking page or localhost, 19 of those servers are IP addresses the advisory never listed, and 16 went into our feed after dropping victims and reassigned hosts. One survivor: [137.220.36.87, from Microsoft's 2023 Flax Typhoon report, still answers for javaupdate.giize[.]com. What went into our feed: 666 records. 78 IPs at confidence 55 to 75 in the default blocklist, 214 domains, 16 file hashes. 356 older or residential-China IPs held back at confidence 35 to 40. Left out: 96 non-Chinese home lines, a SoftEther host that resolves to a Southeast Asian government network, and 14 hashes of public tools.](https://static.wixstatic.com/media/fd5e2b_fb21aee5789a49a2b18b867fe3203f55~mv2.png)
What the advisory says they do
The FBI, CISA, NSA and partners in the UK, Australia, Canada, Japan, New Zealand and Spain describe an operation that mixes automation with patient hands-on work. The same day, the Justice Department said it had seized two of the group's tools, MicroScan and FishHub, under court documents unsealed in the Western District of Pennsylvania.
MicroScan is a Python web application with more than 1,300 vulnerability-checking scripts, in use since at least 2017, aimed at things like WebLogic, Jenkins, Struts, WordPress and old Juniper ScreenOS. Initial access comes from exploit scripts, cross-site scripting that turns a legitimate page into a fake login form, and password spraying against Microsoft Exchange with an open-source tool called EBurst, which tries every door Exchange has: Outlook on the web, the control panel, Exchange Web Services, ActiveSync, Autodiscover, MAPI and the rest.
The fake login form hands the victim a zip file. Inside is live700_v1.exe, which starts a process named DiagTrack.exe, the same name as a real Windows telemetry service, and talks to dns.studiocloud[.]xyz. Persistence is SoftEther, a legitimate VPN client renamed conhost.exe or dllhost.exe and set to reconnect at boot. Email is the prize: a PHP bot called Curlc4 pulls mailboxes through Exchange Web Services and ships them to natcloudservice[.]com, a tool called office-cli reads Microsoft 365 mail using stolen app credentials, and a binary called DC.exe copies the Active Directory database by pretending to be a domain controller. The advisory says the stolen mail archive was restricted so that only IP addresses in Xiamen, China, could open it.
The age problem
The indicator file holds 514 IP addresses, 218 domain names and a few dozen file hashes. The PDF gives each one a first-seen and last-seen date. We sorted the IPs by last seen. 164 were last seen between 2019 and 2022, 175 in 2023 and 173 in 2024. Two were last seen in 2025. None were seen this year.
That is not a criticism. Advisories like this come out of FBI investigations that take years, and the indicators are evidence from those cases. But a defender who loads all 514 into a firewall today is mostly blocking addresses that have changed hands. A rented server from 2022 belongs to somebody else now.
We also looked at who the addresses belong to. 156 geolocate to residential and mobile lines in Xiamen, which lines up with the advisory's Xiamen detail; 134 of them sit in one block, 120.36.248.0/21. 99 are rented servers at Vultr. 85 are in Taiwan, and 80 of those are on ordinary home connections. Home lines in Taiwan showing up in a Chinese operation's infrastructure look like hijacked routers used as relay points, which is how Flax Typhoon has operated before. Those are victims. Blocking them blocks a family in Taiwan, not the operator.
What still answers
The domains tell a different story. We resolved all 218 on October 9. 69 still resolve. Once you drop the ones pointing at Cloudflare, Amazon parking pages, other parked pages and localhost, 23 point at a real server, and 19 of those server addresses do not appear anywhere in the advisory.
A few clusters stand out. Six subdomains of twimg.co[.]uk, a lookalike of the domain Twitter uses for images, resolve to one Vultr server in South Korea, 158.247.199.208, and the subdomain names look like the targets they were built for. Seven names under cktime.ooguy[.]com and javacheck.ooguy[.]com resolve to another Vultr server in South Korea, 64.176.224.126, including names built to look like Active Directory's own DNS records, a pdc._msdcs prefix. A mail cluster under sunmoon[.]website, with mail, smtp, imap and mx names, resolves to 85.131.209.39 at a Japanese host.
One address connects across three years. 137.220.36.87 was in Microsoft's 2023 Flax Typhoon report, and today it still answers for javaupdate.giize[.]com, one of the advisory's SoftEther hosts.
A domain resolving today does not prove the same people control it. Several of these names live on free dynamic-DNS services, where a name can change hands, and a SoftEther dynamic name points at whatever server registered it. One of them, a SoftEther hostname from the advisory, now resolves to a government network in Southeast Asia. That looks like a victim's server running a SoftEther hub the attackers installed, so we kept it out of the feed. The rest of the live servers went in at confidence 55 to 75, not 90, for exactly this reason.
What we held before yesterday
Almost nothing, and we will say so plainly. Of the 756 values in the advisory's tables, 3 were already in our corpus, all from a batch of 13 Flax Typhoon IPs we imported on July 18 from Microsoft's 2023 report. That is an ingest of someone else's research, not a detection. None of the 514 IPs appears in our edge blocks, ever. We do not run Exchange, so our edge is the wrong instrument for EBurst-style spraying; in the last 30 days the only Exchange-path traffic it blocked was nine LeakIX version-fingerprint probes from DigitalOcean on October 4 and 5, which is scanning, not this group.
What we fed, and what we left out
666 records went into our feed under the source research-import-cisa-aa26-281a, plus a separate source, manual-batch-aa26-281a-live-resolution, for the 16 server addresses we found by resolving the advisory's domains. Every record was read back from the index by its primary key after the write, and we downloaded the published CSV files to confirm what a subscriber actually gets.
In the default blocklists: 78 IP addresses, meaning the rented servers seen in 2024 or later plus the live servers above, at confidence 55 to 75; 214 domain names; and 16 file hashes for the group's own tools, including six webshells, DiagTrack.exe, live700_v1.exe, the Curlc4 mail bot, office-cli and DC.exe. Three of the hashes are renamed SoftEther installers, scored at 50 because they may match a legitimate SoftEther download.
Held back from the default IP list: 356 older or residential-China addresses at confidence 35 to 40. Anyone who wants them can pull ips.csv with min_confidence=30. That is your call to make, not ours.
Left out entirely: 80 Taiwanese home lines and 16 other non-Chinese home lines that look like hijacked relays; the government-network SoftEther host; 14 hashes of public open-source tools such as sqlmap, dirsearch, Fscan and JuicyPotato, which would flag every penetration tester who downloads the same release; and one entry in CISA's own file, trust[.]feeee, which is missing its .io and is not a real domain name. Two hostnames that begin with an underscore are in the index but our CSV lane drops them.
If you run a small shop, hunt for these
The IP list is mostly history. The behavior is not. These are the checks that still work.
Look for DNS lookups of softether[.]net names, especially ones that start with vpn followed by a long number, and for servers making outbound connections on ports 443, 992 or 5555 to places they have never talked to before. Look for conhost.exe or dllhost.exe running from anywhere other than C:\Windows\System32.
In Microsoft 365, list every app registration with application-level Mail.Read or full mailbox access and confirm you created each one. office-cli runs on stolen app credentials, so it never trips a sign-in alert for a user.
In Exchange or Microsoft 365 logs, look for failed logins spread across many accounts from a few addresses, on Exchange Web Services, ActiveSync, Autodiscover and the control panel, not just Outlook on the web. On Linux web servers, look for a file at /var/tmp/.sess.zip, a hidden .run file in a web directory, or outbound requests carrying an X-Id header. On the network, any directory replication request from a machine that is not a domain controller is a DCSync attempt until proven otherwise.
The advisory's own advice is the right advice: turn off what you do not use, require multifactor authentication on every mail interface, and patch the internet-facing things first.
The point
A ten-agency advisory is a gift, and this one is unusually detailed about tooling. But an indicator list is a record of where an operator was, and this one mostly records 2023 and 2024. The useful work is to sort it by age, resolve what can still be resolved, keep the victims out, and tell people which rows are live. That took us an evening. It should not be something every small IT shop has to repeat on its own.
We cap our confidence at ninety-five percent as a standing rule, and on infrastructure this old the other five is doing real work.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=aa26-281a-flax-typhoon-integrity-tech-what-still-answers



Comments