Flax Typhoon critical infrastructure intrusion and credential-harvesting campaign
Campaign
Summary
Hide ▲
Show ▼
A Flax Typhoon campaign has been using scanning, intrusion, and credential-harvesting methods against U.S. and foreign critical infrastructure, increasing the risk of unauthorized access to victim networks and cloud services. The operation has relied on Python- and Go-based tools, XSS, and account-targeting utilities to reach Microsoft 365 Cloud environments and harvest credentials. The long-running activity shows coordinated targeting rather than a one-off intrusion. It also raises the likelihood of follow-on access to mailboxes, files, and other sensitive systems.
Related Happenings
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor Meta
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
About this happening:
ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor MetaAbout this happening: ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
Silk Typhoon / Hafnium coordinated intelligence-gathering campaign
Campaign
H score59
First: 27.04.2026 22:56
Last: 27.04.2026 22:56
Sources 1
About this happening:
The Silk Typhoon / Hafnium operation is tied to a coordinated intelligence-gathering campaign spanning February 2020 to June 2021, underscoring a sustained espionage e...
Silk Typhoon / Hafnium coordinated intelligence-gathering campaign
CampaignAbout this happening: The Silk Typhoon / Hafnium operation is tied to a coordinated intelligence-gathering campaign spanning February 2020 to June 2021, underscoring a sustained espionage e...
Latest development: 28.04.2026 15:30
US officials described Silk Typhoon/Hafnium activity from February 2020 to June 2021 as a coordinated intelligence-gathering campaign that targeted US universities and COVID-19 researchers, including a Texas university network, and later expanded into Microsoft Exchange Server vulnerability exploitation. The operation reportedly used stolen mailbox access to search for vaccines, treatments, and testing research, and the FBI said the campaign affected more than 12,700 US organizations.
GopherWhisper China-aligned APT campaign targeting Mongolian government institutions
Campaign
H score30
First: 23.04.2026 12:04
Last: 23.04.2026 12:04
Sources 1
About this happening:
The GopherWhisper campaign is a China-aligned APT operation targeting Mongolian governmental institutions, and it now appears to extend beyond a single compromise to *...
GopherWhisper China-aligned APT campaign targeting Mongolian government institutions
CampaignAbout this happening: The GopherWhisper campaign is a China-aligned APT operation targeting Mongolian governmental institutions, and it now appears to extend beyond a single compromise to *...
Timeline
-
09.10.2026 09:39 2 articles · 2h ago
Flax Typhoon critical infrastructure intrusion and credential-harvesting campaign
Initial DisclosureBy mid-January 2021, the operation was already breaking into victim networks and cloud services with Python- and Go-based utilities. Early access methods included XSS credential harvesting and follow-on account targeting in Microsoft 365 Cloud environments.
Show sources
- FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions — thehackernews.com — 09.10.2026 09:39
- FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions — thehackernews.com — 09.10.2026 09:39