Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

New Salt Typhoon Attacks Leverage Zero-Days and DLL Sideloading

Salt Typhoon is identified as a significant cyber threat targeting global critical infrastructure. Linked to state-sponsored actors from the People's Republic of China, this threat group has conducted campaigns against telecommunications providers,…

Salt Typhoon is identified as a significant cyber threat targeting global critical infrastructure. Linked to state-sponsored actors from the People's Republic of China, this threat group has conducted campaigns against telecommunications providers, energy networks, and government systems, particularly in the United States.

Active since at least 2019, Salt Typhoon, also known as Earth Estries, GhostEmperor, and UNC2286, has demonstrated capabilities in exploiting edge devices and exfiltrating sensitive data across over 80 countries. The group's operations extend into Europe, the Middle East, and Africa, targeting telecoms, government entities, and technology firms.

The group employs custom malware and exploits vulnerabilities in products from vendors such as Ivanti, Fortinet , and Cisco. These activities blend intelligence collection with geopolitical influence.

Salt Typhoon's recent activities include exploiting zero-day vulnerabilities, utilizing obfuscation techniques, and employing lateral movement strategies. These methods have allowed the group to evade detection and maintain access to sensitive environments.

The group's operations have compromised lawful intercept systems, exposed metadata for millions of users, and disrupted essential services. Recent activities observed by Darktrace in a European telecommunications organization included dynamic-link library sideloading and the use of legitimate software for stealth.

Salt Typhoon is identified as a significant cyber threat targeting global critical infrastructure.
Omar Sabbagh · The Levant Herald

The intrusion likely began with the exploitation of a Citrix NetScaler Gateway appliance in early July 2025. The attacker pivoted to Citrix Virtual Delivery Agent hosts in the client's Machine Creation Services subnet.

Initial access activities originated from an endpoint potentially associated with the SoftEther VPN service, suggesting infrastructure obfuscation. The threat actor delivered a backdoor, assessed as SNAPPYBEE, to multiple Citrix VDA hosts. This backdoor was delivered alongside legitimate executable files for antivirus software, using DLL sideloading techniques.

The backdoor communicated via LightNode VPS endpoints for command-and-control, utilizing both HTTP and an unidentified TCP-based protocol. This dual-channel setup aligns with Salt Typhoon's known use of non-standard protocols to evade detection.

The backdoor's HTTP communications involved POST requests with an Internet Explorer User-Agent header and specific Target URI patterns. One of the compromised endpoints contacted a domain associated with Salt Typhoon.

Advertisement

Darktrace's Cyber AI Analyst produced high-confidence detections during the early stages of the intrusion, covering both initial tooling and command-and-control activities. These detections were crucial in neutralizing the threat before it could escalate.

The Cyber AI Analyst autonomously investigated model alerts, discovering initial tooling and command-and-control events, and combining them into unified incidents. Darktrace assesses with moderate confidence that the observed activity aligns with Salt Typhoon's tactics, techniques, and procedures.

Organizations are urged to reassess their threat models, as Salt Typhoon highlights the evolving nature of nation-state cyber operations. Proactive defense strategies relying on behavioral anomaly detection are essential for addressing these threats effectively.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories