• News/
  • https://www.bleepingcomputer.com/news/security/chinese-hackers-abuse-geo-mapping-tool-for-year-long-persistence/

Chinese hackers abuse geo-mapping tool for year-long persistence

BleepingComputer
·
Bill Toulas
·
Published Oct 14, 2025
·
Updated

Chinese state hackers remained undetected in a target environment for more than a year by turning a component in the ArcGIS geo-mapping tool into a web shell. The ArcGIS geographic information system (GIS) is developed by Esri (Environmental Systems Research Institute) and has support for server object extensions (SOE) that can extend the basic functionality. The software is used by municipalities, utilities, and infrastructure operators to collect, analyze, visualize, and manage spatial and geographic data through maps. Researchers at cybersecurity company ReliaQuest are confident that the threat actor is a Chinese APT group and have moderate confidence that it is Flax Typhoon. In a report shared with BleepingComputer, they say that the hackers used valid administrator credentials to log into a public-facing ArcGIS server that was linked to a private, internal ArcGIS server. The attacker used their access to upload a malicious Java SOE acting as a web shell that accepted base64-encoded commands through a REST API parameter (layer) and executed them on the internal ArcGIS server, where they appeared as routine operations. The exchange was protected by a hardcoded secret key, ensuring that only the attackers had access to this backdoor. To establish persistence and extend their capabilities beyond the ArcGIS portal, Flax Typhoon used the malicious SOE to download and install SoftEther VPN Bridge, and registered it as a Windows service that started automatically when the syste...

Read full article

Affected Software

1 affected component
Esri ArcGIS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203