Back to Intelligence

Flax Typhoon / Integrity Technology Group Botnet: Detection and Hardening Guide for Edge Devices

SA
Security Arsenal Team
October 10, 2026
13 min read

On the latest in a series of coordinated advisories, the UK's National Cyber Security Centre (NCSC), the NSA, CISA, the FBI, and allied intelligence partners have publicly attributed a long-running malicious cyber campaign to Integrity Technology Group (ITG), a Beijing-based company operating on behalf of the People's Republic of China. ITG is the operational infrastructure behind the threat actor tracked by Microsoft as Flax Typhoon — a state-aligned actor that has spent years quietly compromising routers, firewalls, NAS appliances, and IoT devices to build a massive, distributed botnet used to conceal espionage and pre-positioning operations against Western targets.

This is not a theoretical warning. The joint advisory documents an actively operating botnet that, at its peak, controlled hundreds of thousands of compromised devices worldwide — including devices in the networks of government agencies, critical infrastructure operators, and commercial enterprises in the US, UK, and allied nations. If your organization exposes edge devices to the internet — and almost every organization does — you need to validate right now whether your routers, VPN concentrators, NAS appliances, and cameras are quietly answering to someone else's command-and-control.

Why Defenders Must Act

Three things make this threat different from commodity botnets like Mirai:

  1. State sponsorship and intent. This infrastructure is not built to sell DDoS capacity. Flax Typhoon uses the botnet to proxy espionage traffic, making malicious activity appear to originate from legitimate residential and small-business IP space — including potentially your corporate egress IPs.
  2. Edge devices are detection blind spots. Routers, firewalls, and IP cameras don't run EDR. In most environments I've assessed over 15 years, these devices have no telemetry collection at all. They are, functionally, unmanaged assets sitting at the trust boundary of the network.
  3. Victim liability. If your compromised edge device is used as a relay for attacks against government or critical infrastructure targets, you inherit the reputational, legal, and incident-response consequences — whether or not you were the intended target.

Technical Analysis

Who Is Integrity Technology Group / Flax Typhoon

Integrity Technology Group is a Chinese company with publicly documented ties to PRC intelligence services. Allied agencies attribute the Flax Typhoon botnet operation to ITG, describing a business model in which the company develops intrusion tooling, operates the botnet infrastructure, and supports state-directed collection requirements. The UK government has specifically warned that ITG poses an ongoing threat to UK networks and has urged organizations to treat edge device hygiene as a national-security-level concern.

How the Operation Works

The attack chain follows a pattern I've seen repeatedly in IR engagements involving edge device compromise:

  1. Initial access via exposed edge devices. The operators exploit known vulnerabilities (and, in some cases, default or weak credentials) on internet-facing routers, firewalls, VPN gateways, NAS devices, DVRs, and IP cameras. Unpatched, end-of-life SOHO and small-enterprise hardware is the primary target — devices that ship with vulnerabilities and never receive updates.
  2. Malware deployment. A purpose-built implant is dropped onto the device, establishing persistence in firmware-writable storage or startup scripts. These implants are lightweight, memory-resident where possible, and designed to survive reboots on embedded Linux platforms.
  3. Command-and-control. Compromised devices beacon to attacker-controlled C2 infrastructure over common ports (frequently TCP 80/443 and non-standard ports masquerading as legitimate services), enabling the operators to remotely issue commands.
  4. Operational use. Devices are used as covert relays — proxying the actor's real traffic, scanning additional targets, exfiltrating data from victim networks, and blending malicious flows into ordinary-looking internet traffic.

What Makes Detection Hard

  • The implants run on embedded Linux (BusyBox-based) systems where defenders rarely collect logs.
  • C2 traffic is low-and-slow, encrypted, and rides ports that perimeter controls treat as benign.
  • Because the botnet is distributed across residential and small-business networks, blocklisting C2 IPs is a losing game — the relay IPs are themselves victims.

Exploitation Status

Confirmed active, ongoing exploitation at global scale. This is not a proof-of-concept or a theoretical capability. Allied governments attribute hundreds of thousands of actively compromised devices to this operation, and takedown/disruption actions have already been executed by law enforcement. Because no single CVE is named in this advisory — the operators exploit a rotating set of known vulnerabilities in unpatched edge hardware — the defensive lesson is architectural: unmanaged, unpatchable edge devices are the attack surface.

Detection & Response

The detections below target the behaviors that are actually observable in a well-instrumented environment: edge devices spawning unexpected processes, making unexpected outbound connections, and the downstream effects seen on internal hosts. Everything here is tuned for high fidelity — I've been in too many SOC war rooms where noisy edge-device rules got disabled within a week.

Sigma Rules

YAML
---
title: Shell Spawned by Web or Management Service on Linux Device
id: 3f8c1a72-9d4e-4b6a-a812-7c5e2d9f01a4
status: experimental
description: Detects embedded/web service processes (common on routers, NAS, and cameras) spawning interactive shells or download utilities, a hallmark of edge device exploitation and webshell activity consistent with Flax Typhoon tradecraft.
references:
  - https://attack.mitre.org/techniques/T1059/
  - https://www.ncsc.gov.uk/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.t1059.004
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/lighttpd'
      - '/httpd'
      - '/nginx'
      - '/mini_httpd'
      - '/goahead'
      - '/uhttpd'
      - '/boa'
      - '/apache2'
  selection_child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/ash'
      - '/wget'
      - '/curl'
      - '/nc'
      - '/ncat'
      - '/busybox'
      - '/python'
      - '/perl'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate CGI or management scripts on NAS devices (rare; tune per-device baseline)
level: high
---
title: Execution from Writable Embedded Device Directories
id: 8b2d5f13-6a7c-4e91-b3d8-1f4a6c2e9075
status: experimental
description: Detects binary execution from /tmp, /var/run, or /dev/shm on Linux systems — the standard staging locations for implants deployed to routers, cameras, and NAS appliances in the ITG/Flax Typhoon botnet.
references:
  - https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.command_and_control
  - attack.t1105
logsource:
  category: process_creation
  product: linux
detection:
  selection:
    Image|startswith:
      - '/tmp/'
      - '/var/tmp/'
      - '/var/run/'
      - '/dev/shm/'
      - '/run/'
  filter_known_tmp_exec:
    Image|contains:
      - '/tmp/pip-'
      - '/tmp/hsperfdata'
  condition: selection and not filter_known_tmp_exec
falsepositives:
  - Some legitimate installers and pip builds execute from /tmp — narrow with filename and hash allowlists
level: high
---
title: Persistence via rc.local or init.d Modification on Linux
id: 5e1a9c48-2f6b-47d3-95e0-4b8d3a1f6c22
status: experimental
description: Detects modification of boot-time persistence locations commonly abused by implants on embedded Linux devices to survive reboots, as observed in edge device botnet operations.
references:
  - https://attack.mitre.org/techniques/T1037/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.persistence
  - attack.t1037.004
logsource:
  category: file_event
  product: linux
detection:
  selection:
    TargetFilename|contains:
      - '/etc/rc.local'
      - '/etc/init.d/'
      - '/etc/rc.d/'
      - '/etc/rcS.d/'
      - '/etc/inittab'
      - '/.bashrc'
      - '/etc/profile.d/'
falsepositives:
  - Package manager operations and legitimate system administration; correlate with change windows
level: medium

KQL Hunt (Microsoft Sentinel / Defender)

Edge devices typically reach Sentinel via Syslog/CEF ingestion from a collector, and their network flows via firewall logs into CommonSecurityLog. This hunt looks for the two highest-signal behaviors: management-plane services spawning shells (from Syslog-augmented hosts), and edge network segments making rare outbound connections — the beacon pattern of a compromised relay.

KQL — Microsoft Sentinel / Defender
// Hunt 1: Edge network segments making rare outbound connections (beacon pattern)
// Tune the subnet list to your DMZ / IoT / branch-office edge segments
let EdgeSubnets = dynamic(["10.10.", "192.168.50.", "172.16."]);
let Lookback = 14d;
CommonSecurityLog
| where TimeGenerated > ago(Lookback)
| where DeviceVendor !in ("Palo Alto Networks", "Fortinet") or true // keep all firewall sources
| where SourceIP startswith_any (EdgeSubnets)
| where isnotempty(DestinationIP)
| summarize ConnectionCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
            UniqueSources = dcount(SourceIP), Ports = make_set(DestinationPort)
  by DestinationIP, DestinationPort
| where ConnectionCount between (10 .. 2000)  // low-and-slow beaconing, not bulk traffic
| join kind=leftanti (
    CommonSecurityLog
    | where TimeGenerated between (ago(90d) .. ago(14d))  // suppress destinations seen historically
    | summarize by DestinationIP
) on DestinationIP
| project DestinationIP, DestinationPort, ConnectionCount, FirstSeen, LastSeen, UniqueSources, Ports
| order by FirstSeen asc;

// Hunt 2: Syslog-ingested Linux hosts where a web/management service spawns a shell or downloader
Syslog
| where TimeGenerated > ago(7d)
| where ProcessName in~ ("lighttpd", "httpd", "nginx", "mini_httpd", "goahead", "uhttpd", "boa")
    or SyslogMessage has_any ("lighttpd", "mini_httpd", "goahead", "uhttpd")
| where SyslogMessage has_any ("/bin/sh", "/bin/bash", "/bin/ash", "wget ", "curl ", "/tmp/", "chmod +x")
| project TimeGenerated, Computer, ProcessName, SyslogMessage
| order by TimeGenerated desc;

// Hunt 3: Managed endpoints proxying toward edge devices at unusual times (downstream relay use)
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where RemotePort in (22, 23, 80, 443, 8080, 8443)
| where RemoteIPType == "Private" or RemoteIPType == "LinkLocal"
| join kind=inner (
    DeviceNetworkEvents
    | where TimeGenerated > ago(7d)
    | summarize arg_max(TimeGenerated, *) by DeviceName, RemoteIP
) on DeviceName, RemoteIP
| summarize Connections = count(), Hours = make_set(bin(TimeGenerated, 1h)) by DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName
| where Connections > 20 and InitiatingProcessFileName !in ("svchost.exe", "chrome.exe", "msedge.exe", "firefox.exe")
| order by Connections desc;

Velociraptor VQL

Deploy this artifact against Linux infrastructure and any edge-adjacent systems (jump boxes, management VLAN hosts) to surface implant staging artifacts, unexpected listeners, and boot-time persistence in one sweep.

VQL — Velociraptor
-- Flax Typhoon / edge device implant triage
-- Surfaces: executables staged in writable dirs, unexpected listeners, rc/init persistence

// 1. Executables staged in world-writable locations
LET staged = SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs=['/tmp/*', '/var/tmp/*', '/dev/shm/*', '/var/run/*'])
WHERE NOT IsDir
  AND Mode =~ 'x'
  AND NOT FullPath =~ '(pip-|systemd-private)'

// 2. Listening sockets and their owning processes
LET listeners = SELECT Pid, Name, Family, Address, Port, Status
FROM netstat()
WHERE Status = 'LISTEN'
  AND Port NOT IN (22, 53, 80, 443, 8080)  // baseline your expected services

// 3. Boot persistence artifacts modified recently
LET persistence = SELECT FullPath, Size, Mtime
FROM glob(globs=['/etc/rc.local', '/etc/init.d/*', '/etc/rc.d/*', '/etc/profile.d/*'])
WHERE Mtime > Now() - 86400 * 30

SELECT 'STAGED_EXEC' AS Category, FullPath AS Artifact, Size, Mtime FROM staged
UNION ALL
SELECT 'LISTENER' AS Category, Name AS Artifact, Port AS Size, NULL AS Mtime FROM listeners
UNION ALL
SELECT 'PERSISTENCE' AS Category, FullPath AS Artifact, Size, Mtime FROM persistence

Remediation

There is no single patch here — the fix is removing the conditions that let ITG's operators treat your edge devices as free infrastructure. Prioritize in this order:

1. Inventory and Firmware Audit (Day 0)

You cannot protect what you cannot see. Build an authoritative inventory of every internet-facing device — routers, firewalls, VPN gateways, NAS, cameras, DVRs — and record firmware versions. Anything end-of-life or unpatchable goes on the replacement list immediately. The joint advisory is unambiguous: EOL hardware is the primary entry point.

2. Verification and Cleanup Script (Linux / Edge Devices)

Run this on Linux-based appliances and management hosts to check for the implant behaviors described above and harden the device. Review output before taking destructive actions on production gear.

Bash / Shell
#!/bin/bash
# Edge device compromise triage + hardening — review findings before remediation
# Run as root on the device or via your config management (Ansible/Salt)

echo "=== [1] Executables in writable staging dirs ==="
find /tmp /var/tmp /dev/shm /var/run -type f -perm -111 2>/dev/null | grep -v -E 'pip-|systemd-private'

echo "=== [2] Persistence in boot scripts (modified last 30 days) ==="
find /etc/rc.local /etc/init.d/ /etc/rc.d/ /etc/profile.d/ /etc/crontab /etc/cron.d/ -type f -mtime -30 2>/dev/null

echo "=== [3] Unexpected listening services ==="
ss -tulpn 2>/dev/null | awk 'NR>1 {print}' | grep -v -E ':(22|53|80|443|8080)\b'

echo "=== [4] Processes with deleted binaries (common for memory-resident implants) ==="
ls -l /proc/*/exe 2>/dev/null | grep '(deleted)'

echo "=== [5] Outbound connections from non-service processes ==="
ss -tnp 2>/dev/null | grep ESTAB | grep -v -E 'sshd|nginx|httpd'

echo "=== [6] Suspicious crontab entries ==="
crontab -l 2>/dev/null; for u in $(cut -f1 -d: /etc/passwd); do crontab -u "$u" -l 2>/dev/null | grep -E 'wget|curl|/tmp|http'; done

echo "=== [7] Hardening: disable telnet and unused management interfaces ==="
systemctl list-unit-files 2>/dev/null | grep -E 'telnet|tftp' | grep enabled
pkill -f telnetd 2>/dev/null && echo "telnetd killed"

echo "=== [8] Hardening: verify firmware is current ==="
uname -a
echo "MANUAL CHECK REQUIRED: compare firmware against vendor advisory for your model"
echo "=== Triage complete. Preserve /tmp and process memory before rebooting. ==="

Critical DFIR note: If findings in steps 1–5 indicate compromise, do not reboot the device until you have captured volatile data. Many edge implants are partially memory-resident; an unplanned reboot destroys your best evidence and your attribution trail. Treat confirmed compromise as a formal incident.

3. Architectural Hardening (Week 1–4)

  • Isolate edge devices into a dedicated management VLAN. Management interfaces (web UIs, SSH, telnet) must never be reachable from the internet. If remote administration is a business requirement, front it with a hardened VPN or zero-trust access broker — not the device's own login page.
  • Egress filtering. Routers and cameras have no business initiating outbound connections to arbitrary internet destinations. Enforce default-deny egress from edge/IoT segments and alert on violations — this kills the beacon channel even on a compromised device.
  • Replace EOL hardware. Any device past end-of-support is a standing invitation. The NCSC and partner agencies explicitly call this out; budget accordingly.
  • Centralize logging. Forward syslog from every edge device to your SIEM. If a device cannot log, that is a procurement disqualifier going forward.
  • Credential hygiene. Rotate all edge device credentials, kill default accounts, and disable password-based SSH in favor of keys.
  • Threat intel integration. Subscribe to CISA, NCSC, and FBI joint advisories (search "Flax Typhoon joint advisory" at cisa.gov and ncsc.gov.uk) and ingest the published indicators — file hashes, C2 domains, and IP addresses — into your firewall and DNS filtering layers. Indicators from official advisories are high-confidence and low-noise.

4. If You Find a Compromised Device

  1. Isolate, don't reboot. Segment the device at the switch/firewall level.
  2. Capture forensics. Volatile memory, running processes, network connections, and the filesystem image where the platform permits.
  3. Check downstream impact. Review what internal hosts the device could see and whether it was used as a relay into your network — examine firewall and NetFlow records for the preceding 90 days.
  4. Report it. US organizations report to CISA (cisa.gov/report) and the FBI's IC3; UK organizations to the NCSC. Government attribution efforts — including actions against ITG — are built on victim reporting.
  5. Rebuild, don't clean. Re-flash firmware from vendor-verified sources or replace the device. Embedded implants survive half-measures.

The Bottom Line

The allied warning about Integrity Technology Group is a forcing function. State actors have industrialized the compromise of edge devices precisely because defenders ignore them. The organizations that come out of this clean will be the ones that treat routers, firewalls, and cameras as first-class assets in their security program — inventoried, patched, logged, and egress-restricted. Everyone else is, knowingly or not, renting out rack space on their perimeter to a foreign intelligence service.

Related Resources

Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.