The FBI and Department of Justice say they seized seven domains and blocked access to platforms used by the China-linked APT group Flax Typhoon to scan, and in some cases infiltrate, U.S. critical infrastructure. The public summary does not disclose a CVE, specific malware hash set, or the seized domain list in the provided excerpt, so defenders should treat this as an active infrastructure-disruption event rather than a single-patch vulnerability story.
The operational risk is straightforward: state-nexus actors often convert exposed routers, VPN gateways, cameras, NAS appliances, Linux jump boxes, and unmanaged IoT into relay nodes. Those nodes are then used for reconnaissance, password spraying, vulnerability scanning, command-and-control proxying, and low-and-slow access into energy, water, healthcare, telecom, transportation, and manufacturing environments. A domain seizure removes some capability, but it does not remove compromised devices, valid credentials, persistence, firewall policy gaps, or vulnerable edge services already in place.
Act now if you operate critical infrastructure, manage perimeter appliances, run a SOC, or rely on flat OT/IT network paths. The immediate defensive goal is to find relay behavior: outbound scanning from assets that should never scan, unexpected SOCKS/SSH tunnel listeners, persistence on Linux edge devices, and connections to newly registered, low-reputation, or law-enforcement-sinkholed infrastructure.
Technical analysis
Affected products and platforms
No CVE identifier is present in the source summary, and none should be invented. Based on the described activity, the relevant exposure surface is not one vendor patch level; it is the class of systems frequently abused as operational relay boxes and initial access brokers:
- Internet-facing routers, firewalls, VPN concentrators, SD-WAN edges, and remote access gateways
- Linux servers and appliances with SSH exposed or weak credential hygiene
- NAS, NVR, IP camera, and embedded device fleets with outdated firmware or default credentials
- OT-adjacent jump hosts, engineering workstations, historian connectors, and remote maintenance servers
- Cloud VPS instances abused for scanning, tunneling, staging, and redirector roles
The most important common denominator is reachability: devices that can initiate outbound connections broadly, accept inbound management from the internet, or bridge IT and OT zones are high-value relay candidates.
How the activity works from a defender's perspective
The reported pattern is infrastructure-enabled intrusion support. Typical observable stages include:
- Reconnaissance and validation: compromised relays scan public IP space for open management ports, weak services, and known appliance fingerprints.
- Access and relay setup: operators deploy lightweight tunneling or proxy tooling, add SSH keys or cron/systemd persistence, and disable noisy logging where possible.
- Operational use: the relay scans internal ranges, proxies traffic to C2 or redirectors, brute-forces remote access, or stages tooling for follow-on intrusion.
- Disruption response: when domains are seized, actors rotate to backup domains, raw IP C2, fast-flux DNS, bulletproof VPS, or compromised legitimate sites.
Because a takedown can trigger rapid reconstitution, the week after a seizure is often noisy: defenders may see sinkhole hits, failed DNS lookups, fallback to hard-coded IPs, credential replay from previously accessed accounts, and new scanning sources replacing seized nodes.
Exploitation status
The provided summary confirms government disruption of malicious tools and domains tied to active critical-infrastructure targeting. It does not state a CISA KEV entry, CVSS score, vendor advisory, or public proof-of-concept exploit. Treat exploitation as confirmed at the campaign level, but avoid mapping your response to a fabricated CVE. Track the FBI, DOJ, CISA, NSA, and vendor PSIRT releases for the seized-domain indicators and any newly attributed vulnerabilities.
Detection and response
The detections below are intentionally behavior-based. They avoid assuming specific seized domains and instead focus on relay tradecraft: scanners and proxies on inappropriate assets, Linux persistence on edge devices, suspicious tunnel ports, DNS fallout after takedown, and assets initiating traffic inconsistent with their role.
---
title: Linux Edge Scanner or Proxy Tool Execution
tid: 4f19a8c2-6c64-4a84-9f63-flaxrelay001
status: experimental
description: Detects execution of network scanners or lightweight proxy/tunnel tools commonly used on compromised Linux edge devices and relay nodes.
references:
- https://attack.mitre.org/techniques/T1046/
- https://attack.mitre.org/techniques/T1090/
author: Security Arsenal
date: 2026/10/15
tags:
- attack.discovery
- attack.t1046
- attack.command_and_control
- attack.t1090
logsource:
category: process_creation
product: linux
detection:
selection_images:
Image|endswith:
- '/nmap'
- '/masscan'
- '/zmap'
- '/zgrab'
- '/frpc'
- '/chisel'
- '/microsocks'
- '/3proxy'
- '/gost'
- '/iodine'
selection_cli:
CommandLine|contains:
- ' -D '
- ' -R '
- ' -L '
- '--socks5'
- '--server'
- '--mode socks'
- '--masscan'
- '--rate='
condition: selection_images or selection_cli
falsepositives:
- Authorized vulnerability scanners and network assessments
- Admin SSH port forwarding from approved jump hosts
level: high
---
title: Suspicious Tunnel Listener on Edge or Server
tid: 7d2b61aa-13d9-49f0-aa11-flaxrelay002
status: experimental
description: Detects listening sockets associated with SOCKS, SSH tunnel, Tor, Shadowsocks, or reverse proxy behavior on servers and edge devices that should not proxy traffic.
references:
- https://attack.mitre.org/techniques/T1090/
- https://attack.mitre.org/techniques/T1572/
author: Security Arsenal
date: 2026/10/15
tags:
- attack.command_and_control
- attack.t1090
- attack.t1572
logsource:
category: network_connection
product: linux
detection:
selection_ports:
DestinationPort:
- 1080
- 1081
- 8080
- 8388
- 9050
- 9051
- 4444
selection_listen:
Initiated: false
filter_approved:
Image|endswith:
- '/sshd'
- '/nginx'
- '/haproxy'
- '/envoy'
condition: selection_ports and selection_listen and not filter_approved
falsepositives:
- Legitimate proxy services and load balancers
- Approved remote access tunnel gateways
level: medium
---
title: Linux Edge Persistence in Cron Systemd or SSH Keys
tid: 91c4e07f-6e28-4d1f-9cf7-flaxrelay003
status: experimental
description: Detects creation or modification of cron, systemd, rc.local, shell profile, or authorized_keys artifacts consistent with persistence on compromised Linux edge systems.
references:
- https://attack.mitre.org/techniques/T1053/
- https://attack.mitre.org/techniques/T1543/
- https://attack.mitre.org/techniques/T1098/
author: Security Arsenal
date: 2026/10/15
tags:
- attack.persistence
- attack.t1053.003
- attack.t1543.002
- attack.t1098.004
logsource:
category: file_event
product: linux
detection:
selection_paths:
TargetFilename|startswith:
- '/etc/cron.d/'
- '/etc/cron.daily/'
- '/etc/cron.hourly/'
- '/var/spool/cron/'
- '/etc/systemd/system/'
- '/usr/lib/systemd/system/'
- '/etc/rc.local'
- '/etc/profile.d/'
selection_keys:
TargetFilename|endswith:
- '/.ssh/authorized_keys'
- '/.ssh/authorized_keys2'
condition: selection_paths or selection_keys
falsepositives:
- Configuration management and package installation
- Approved key rotation and hardening changes
level: high
let lookback = 14d;
let suspicious_ports = dynamic([1080,1081,8080,8388,9050,9051,4444,2323,5555]);
let edge_roles = dynamic(['firewall','router','vpn','gateway','nas','nvr','camera','ot-jump','jumpbox']);
let proc =
DeviceProcessEvents
| where TimeGenerated >= ago(lookback)
| where ProcessCommandLine has_any ('masscan','zmap','zgrab','nmap -','frpc','chisel','microsocks','3proxy','gost',' --server',' --socks5',' -D ',' -R ',' -L ')
| project DeviceName, ProcessCommandLine, FileName, FolderPath, AccountName, TimeGenerated;
let net =
DeviceNetworkEvents
| where TimeGenerated >= ago(lookback)
| where RemotePort in (suspicious_ports) or LocalPort in (suspicious_ports)
| extend DeviceRole = tolower(extract(@'(?i)(firewall|router|vpn|gateway|nas|nvr|camera|jump|ot)', 0, DeviceName))
| where DeviceRole != '' or InitiatingProcessCommandLine has_any ('ssh','frpc','chisel','microsocks','3proxy','gost','socat')
| project DeviceName, DeviceRole, RemoteIP, RemoteUrl, RemotePort, LocalPort, InitiatingProcessFileName, InitiatingProcessCommandLine, TimeGenerated;
let dns =
CommonSecurityLog
| where TimeGenerated >= ago(lookback)
| where isnotempty(DestinationHostName)
| extend host = tolower(DestinationHostName)
| where host matches regex @'^[a-z0-9-]{18,}\.(top|xyz|icu|zip|lol|cam|bond|quest)$' or host has_any ('sinkhole','seized','flax')
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Hits=count(), Sources=dcount(SourceIP) by DestinationHostName, DestinationIP
| where Hits <= 3 or Sources >= 1;
proc
| union net
| union dns
| sort by TimeGenerated desc
-- Linux edge/relay hunt for Flax Typhoon-style scanning, tunneling, persistence, and listeners
LET procs = SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(masscan|zmap|zgrab|nmap|frpc|chisel|microsocks|3proxy|gost|socat|ssh.*-[DRL])'
OR Exe =~ '(?i)/(frpc|chisel|microsocks|3proxy|gost|zmap|masscan)$';
LET persist = SELECT FullPath, Size, Mtime, Mode
FROM glob(globs=[
'/etc/cron.d/*',
'/etc/cron.daily/*',
'/etc/systemd/system/*.service',
'/usr/lib/systemd/system/*.service',
'/etc/profile.d/*',
'/home/*/.ssh/authorized_keys',
'/root/.ssh/authorized_keys'
])
WHERE Mtime > now() - 1209600
AND NOT FullPath =~ '(?i)(logrotate|man-db|apt|dpkg|snap|cron|systemd-|ssh|cloud-init)';
LET listeners = SELECT Pid, Name, Address, Port, Status
FROM netstat()
WHERE Status =~ '(?i)listen'
AND Port in (1080,1081,8080,8388,9050,9051,4444,2323,5555)
AND NOT Name =~ '(?i)(sshd|nginx|haproxy|envoy|squid)';
SELECT 'process' AS Artifact, * FROM procs
UNION ALL
SELECT 'persistence' AS Artifact, * FROM persist
UNION ALL
SELECT 'listener' AS Artifact, * FROM listeners
#!/usr/bin/env bash
# Flax Typhoon relay audit for Linux edge/jump systems. Default is read-only.
# Set REMEDIATE=1 only after Change Control approval.
set -euo pipefail
REMEDIATE="${REMEDIATE:-0}"
REPORT="/var/tmp/edge-relay-audit-$(date +%F-%H%M%S).txt"
{
echo "== Host =="; hostnamectl || true
echo; echo "== Suspicious processes =="
ps -eo pid,ppid,user,comm,args | grep -Ei 'masscan|zmap|zgrab|frpc|chisel|microsocks|3proxy|gost|socat|ssh .*-[DRL]' | grep -v grep || true
echo; echo "== Suspicious listeners =="
ss -lntup | grep -E ':(1080|1081|8080|8388|9050|9051|4444|2323|5555)\b' || true
echo; echo "== Recent persistence artifacts =="
find /etc/cron.d /etc/cron.daily /etc/systemd/system /usr/lib/systemd/system /etc/profile.d -type f -mtime -14 -printf '%TY-%Tm-%Td %TH:%TM:%TS %p\n' 2>/dev/null | sort || true
find /root/.ssh /home/*/.ssh -maxdepth 1 -name 'authorized_keys*' -mtime -30 -printf '%TY-%Tm-%Td %TH:%TM:%TS %p\n' 2>/dev/null || true
echo; echo "== Recent outbound connection summary =="
ss -tnp state established | awk 'NR>1 {print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr | head -50 || true
} | tee "$REPORT"
if [ "$REMEDIATE" = "1" ]; then
# Stop common relay tooling; verify business impact first.
pkill -f 'masscan|zmap|zgrab|frpc|chisel|microsocks|3proxy|gost' 2>/dev/null || true
# Disable world-writable or unauthorized systemd units created in last 14 days; review before reboot.
find /etc/systemd/system /usr/lib/systemd/system -type f -mtime -14 -name '*.service' -print0 2>/dev/null | while IFS= read -r -d '' unit; do
base="$(basename "$unit")"
case "$base" in sshd.service|systemd-*|cron.service|NetworkManager.service|cloud-init*) continue;; esac
systemctl disable --now "$base" 2>/dev/null || true
done
# Require key-only SSH and disable direct root password login; ensure you have console access first.
install -d -m 700 /etc/ssh/sshd_config.d
cat >/etc/ssh/sshd_config.d/60-edge-hardening.conf <<'EOF'
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
AllowTcpForwarding no
X11Forwarding no
PermitTunnel no
EOF
sshd -t && systemctl reload sshd
# Default-deny egress for non-essential ports; adapt to approved proxy/DNS/NTP/EDR destinations.
if command -v nft >/dev/null 2>&1; then
nft add table inet edge_filter 2>/dev/null || true
nft add chain inet edge_filter output '{ type filter hook output priority 0; policy accept; }' 2>/dev/null || true
nft add rule inet edge_filter output tcp dport '{1080,1081,8388,9050,9051,4444,2323,5555}' counter drop 2>/dev/null || true
fi
echo "REMEDIATE mode completed; report: $REPORT"
else
echo "Audit only. Re-run with REMEDIATE=1 after approval. Report: $REPORT"
fi
Remediation and hardening priorities
-
Pull official indicators first. Ingest FBI/DOJ/CISA releases, seized-domain notices, sinkhole destinations, and any vendor advisories into your SIEM, DNS firewall, EDR blocklists, and proxy controls. Do not rely on screenshots or reposted IOC lists; validate against the government PDF or court/seizure notices when published.
-
Hunt backward before you block forward. Search at least 90 days of DNS, firewall, proxy, NetFlow, EDR, VPN, and SSH logs for scanning sources, tunnel ports, failed domain resolutions after the takedown, and authentication anomalies from new VPS or residential-proxy ASNs. Preserve evidence before rebooting suspected relays.
-
Constrain edge-device behavior. Routers, cameras, NAS, NVRs, VPN concentrators, and OT jump hosts should not run scanners, open SOCKS listeners, browse the internet, or initiate broad outbound connections. Enforce default-deny egress with explicit allows for DNS, NTP, patching, EDR, backup, and vendor update endpoints.
-
Remove persistence and rotate trust. On suspected Linux edge systems, audit cron, systemd, rc.local, profile scripts, authorized_keys, sudoers, and hidden users. Rotate local and service credentials, revoke unknown SSH keys, reissue certificates on exposed gateways, and invalidate VPN sessions and tokens. Reimage devices when integrity is uncertain; firmware reset alone is not enough if credentials were harvested.
-
Reduce the attack surface that feeds relay networks. Disable Telnet, UPnP, WPS, unused admin interfaces, WAN-side management, and default accounts. Segment OT from IT with deny-by-default rules, brokered access, MFA at the boundary, jump-host recording, and no direct internet exposure for historians, PLCs, HMIs, or engineering stations.
-
Patch what is actually exposed, not what is trending. Because no CVE is named in the summary, prioritize current firmware and appliance updates for perimeter and remote-access products, then reconcile against vendor PSIRT and CISA KEV for actively exploited issues affecting your exact models. Apply emergency mitigations only from the vendor advisory for your platform.
-
Prepare for actor reconstitution. After seizures, expect fallback domains, raw-IP C2, compromised legitimate sites, and fresh scanning nodes. Create detections for behavior rather than domains, alert on first-seen egress destinations from critical assets, and escalate any critical-infrastructure relay compromise as an incident-response event with legal, OT safety, communications, and executive stakeholders engaged.
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.