Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The U.S. Treasury Department sanctioned Beijing-based Integrity Technology Group, Inc. on January 3, 2025, alleging that infrastructure linked to the company supported intrusions attributed to the Chinese state-sponsored cyber group Flax Typhoon.
The action was an Office of Foreign Assets Control (OFAC) designation—not a criminal conviction, export-control listing, or blanket ban on Chinese cybersecurity products. It mainly affects the company’s property and transactions involving U.S. persons or the United States.
What the U.S. government announced
OFAC designated Integrity Technology Group under Executive Order 13694, as amended by Executive Order 13757. Treasury said the Beijing-based company’s infrastructure was used by Flax Typhoon during computer-network exploitation activity against multiple victims between summer 2022 and fall 2023, including organizations in U.S. critical-infrastructure sectors.
Treasury’s announcement does not say that Integrity Tech itself personally carried out every intrusion. The allegation is more specific: infrastructure associated with the company supported or enabled activity attributed to Flax Typhoon. That distinction matters when assessing legal, business, and cybersecurity risk.
The designation remains a January 2025 enforcement action, not a new sanction announced in 2026. Read Treasury’s announcement for the government’s full description of the action.
#1 Best Overall
Who is Flax Typhoon?
Treasury describes Flax Typhoon as a Chinese state-sponsored malicious cyber group active since at least 2021. The group has targeted organizations in critical-infrastructure sectors and operated against victims in North America, Europe, Africa, and Asia, with a particular focus on Taiwan.
According to Treasury, Flax Typhoon has exploited publicly known vulnerabilities to gain initial access and used legitimate remote-access software to maintain persistence. Security vendors may use different names for overlapping activity; secondary reporting has associated Flax Typhoon with names including Ethereal Panda and RedJuliett, but those labels should not automatically be treated as interchangeable.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesThe reported botnet connection
Secondary reporting linked Integrity Tech infrastructure to the management of a large botnet made up of compromised internet-connected devices. The reported devices included routers, firewalls, IP cameras, digital video recorders, network-attached storage devices, and Linux-based servers.
The botnet was described as based on or related to publicly available Mirai malware code. The reported figures included:
- More than 260,000 active nodes at one point;
- More than 1.2 million compromised devices listed in command-and-control databases, including inactive devices; and
- Approximately 385,000 devices based in the United States in the database.
These figures, reported in connection with a joint advisory and secondary coverage, describe the situation at the time—not the botnet’s current size. Active nodes, total listed devices, and U.S.-based devices are different measurements. A botnet can support disruptive activity such as denial-of-service attacks, but compromised infrastructure can also provide concealment, routing, or access for other operations.
See CSO Online’s reporting for additional context on the botnet allegations.
What the OFAC sanctions do
In practical terms, the designation generally means:
Rank #3
- Property and interests in property belonging to Integrity Tech that are in the United States or controlled by U.S. persons are blocked.
- U.S. persons generally may not transact with the designated company.
- Transactions involving blocked property may create reporting obligations.
- Entities owned directly or indirectly 50% or more by one or more blocked persons are generally treated as blocked under OFAC’s 50 Percent Rule, even if they are not separately listed.
The restrictions can affect banks, cloud providers, hosting companies, technology suppliers, contractors, and other businesses that provide services to or process payments for the designated party. Exemptions, general licenses, or specific licenses may apply to particular transactions, so companies should check current OFAC guidance and obtain advice from qualified sanctions counsel before acting.
OFAC sanctions are not automatically the same as export controls. This action does not create a blanket prohibition on all Chinese technology companies, all Chinese cybersecurity products, or every customer that has ever interacted with Integrity Tech.
What it means for U.S. companies and customers
The designation does not establish that every Integrity Tech customer or business partner violated U.S. law. It does, however, create a reason for companies to review their exposure carefully.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #4
Potentially affected parties may include:
- U.S. persons buying services directly from Integrity Tech;
- Companies paying the designated entity or providing it services;
- Banks and payment processors handling related transactions;
- Cloud, telecommunications, hosting, or infrastructure providers whose services benefit the company; and
- Businesses with subsidiaries, investors, resellers, or other ownership relationships that trigger the 50 Percent Rule.
Screening should not rely only on an English-language brand name. A review should cover legal names, aliases, ownership, subsidiaries, counterparties, payment routes, resellers, and service providers. Because sanctions exposure can be fact-specific and civil liability may apply without proof of intent, transaction-specific legal review is important.
Practical checklist for businesses
- Screen counterparties. Check OFAC lists and applicable ownership information before onboarding vendors, paying invoices, or renewing contracts.
- Review supply chains. Identify whether a parent company, subsidiary, reseller, cloud provider, or hidden service provider is involved.
- Trace payment routes. Review banks, U.S. persons, intermediaries, and infrastructure used to complete transactions.
- Patch exposed appliances. Prioritize internet-facing routers, firewalls, cameras, DVRs, NAS devices, and Linux-based edge systems.
- Inventory unmanaged devices. Isolate or replace equipment that cannot be patched or monitored.
- Audit remote access. Review VPNs, remote-desktop services, legitimate remote-management tools, authentication, and unusual geographic activity.
- Monitor network appliances. Look for unexpected outbound connections or command-and-control behavior from devices that normally should not initiate broad internet traffic.
- Segment critical systems. Prevent compromised edge devices from providing easy lateral movement into sensitive networks.
- Prepare an escalation plan. Coordinate sanctions, legal, procurement, and incident-response teams before a potential match or compromise becomes a payment or reporting crisis.
Security tools can help with asset discovery, vulnerability management, endpoint detection, or network monitoring, but none of them substitutes for OFAC screening or legal advice.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How this differs from other China-related cyber sanctions
The Integrity Tech action should not be conflated with other U.S. designations involving different companies or threat groups. Treasury sanctioned Wuhan Xiaoruizhi Science and Technology Company and two employees in March 2024 in connection with APT31-related activity. It sanctioned Sichuan Silence Information Technology Company and an employee in December 2024 over firewall compromises.
Best Value
On January 17, 2025, Treasury designated Sichuan Juxinhe Network Technology in connection with Salt Typhoon, along with cyber actor Yin Kecheng. In March 2025, Treasury sanctioned Shanghai Heiying Information Technology and Zhou Shuai in connection with data brokerage involving sensitive U.S. networks. These actions form part of a broader approach aimed not only at alleged hackers, but also at infrastructure providers, contractors, and other cyber enablers.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →See Treasury’s Salt Typhoon-related announcement and its March 2025 announcement for distinctions among the cases.
Why the designation matters
The case illustrates a shift toward targeting the commercial and technical ecosystem that allegedly supports state-backed cyber operations. For businesses, the lesson is twofold: sanctions compliance requires more than a simple name search, while cyber defense requires visibility into internet-facing appliances, unmanaged IoT devices, remote-access tools, and network traffic.
The designation is an allegation-backed financial restriction, not a criminal verdict and not proof that every commercial activity associated with Integrity Tech was malicious. Its practical significance lies in the restrictions on property and transactions—and in the warning that companies enabling or supporting cyber operations may themselves become targets of U.S. sanctions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

