China's Flax Typhoon Turns Geo-Mapping Server into a Backdoor
ID: 445b6873-7dcb-5f45-a022-c4e87b09018a
STIX ID: report--445b6873-7dcb-5f45-a022-c4e87b09018a
Feed Name: Dark Reading
Reliaquest researchers uncovered a prolonged intrusion by the Chinese APT group Flax Typhoon that converted an ArcGIS Java SOE into a persistent web shell after compromising an administrator account. The attackers used the public-facing portal to forward disguised commands to an internal ArcGIS server, created a hidden workspace with a hardcoded key, and ensured persistence by embedding the malicious component into system backups; remediation required rebuilding the server stack and deploying custom detections. The report warns that while the component was ArcGIS-specific, the persistence tactic can apply to any publicly exposed application and stresses strong credential hygiene, multifactor authentication, least privilege, and behavioral analytics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
