Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, News

Canada Co-Signs Advisory on China-Linked Flax Typhoon Email Theft: What Canadian Organizations Must Do

What Happened

The FBI seized seven domains tied to Flax Typhoon, a China-linked group. BleepingComputer reports the domains ran two tools. MicroScan is a Python scanner with more than 1,300 scripts. FishHub supports spear-phishing and malware delivery. U.S. authorities say China-based Integrity Technology Group operated the infrastructure.

A joint advisory also describes a web application which gives third parties access to stolen email. The Hacker News reports CISA added five flaws to its Known Exploited Vulnerabilities catalog, with a federal deadline of October 11. The flaws sit in ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND. The actors also used password spraying against Microsoft Exchange servers and set up persistence through VPN software.

Why This Matters for Canadian Organizations

The Hacker News lists Canada among seven co-signers, alongside Australia, Japan, New Zealand, Spain, the UK, and the US. Other coverage names only the FBI, CISA, and the NSA, so confirm the Canadian role in the advisory text. Either way, the targets include critical manufacturing, healthcare, IT, education, and government, and the advisory names North America as a victim region.

Five of the eight flaws date from 2015 to 2023. Old software on forgotten servers is the opening. Canadian municipalities, hospitals, and manufacturers often run aging file servers, collaboration tools, and Exchange. A stolen mailbox also exposes personal information, which triggers PIPEDA breach reporting duties. Federally regulated firms should treat the actor’s OT positioning as a resilience issue under OSFI Guideline B-13.

What to Do

Search your asset inventory for the five newly listed products and the three older flaws, including Shellshock and Ivanti Pulse Connect Secure. Patch or retire anything exposed to the internet. Enforce multifactor authentication on Exchange and block legacy authentication to stop password spraying. Review VPN software for unknown accounts. Check logs against the advisory’s indicators of compromise. For related coverage, see our News archive and Trends coverage.

Enjoy this article? Don’t forget to share.