logo

SOE-phisticated Persistence: Inside Flax Typhoon's ArcGIS Compromise

ID: 7397b640-4fc5-5541-afa8-c630c54e7399

STIX ID: report--7397b640-4fc5-5541-afa8-c630c54e7399

Feed Name: ReliaQuest Blog

Threat Score
90/100

Date Published: 2025-10-14

Date Updated: 2026-04-29

...
...

This report describes a sophisticated, year-long intrusion by a China-linked APT (Flax Typhoon) that converted a trusted ArcGIS Java server object extension into a gated web shell, used a renamed SoftEther VPN executable for persistent VPN-based C2, harvested credentials and performed lateral movement across internal networks; it emphasizes the need to treat public-facing applications as high-risk assets, shift from IOC-based detection to behavioral analytics, and implements remediation and detections alongside MITRE ATT&CK mappings and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.