New Salt Typhoon Attacks Leverage Zero-Days and DLL Sideloading
Salt Typhoon is identified as a significant cyber threat targeting global critical infrastructure. Linked to state-sponsored actors from the People's Republic of China, this threat group has conducted campaigns against telecommunications providers,…
Salt Typhoon is identified as a significant cyber threat targeting global critical infrastructure. Linked to state-sponsored actors from the People's Republic of China, this threat group has conducted campaigns against telecommunications providers, energy networks, and government systems, particularly in the United States.
Active since at least 2019, Salt Typhoon, also known as Earth Estries, GhostEmperor, and UNC2286, has demonstrated capabilities in exploiting edge devices and exfiltrating sensitive data across over 80 countries. The group's operations extend into Europe, the Middle East, and Africa, targeting telecoms, government entities, and technology firms.
The group employs custom malware and exploits vulnerabilities in products from vendors such as Ivanti, Fortinet , and Cisco. These activities blend intelligence collection with geopolitical influence.
Salt Typhoon's recent activities include exploiting zero-day vulnerabilities, utilizing obfuscation techniques, and employing lateral movement strategies. These methods have allowed the group to evade detection and maintain access to sensitive environments.
The group's operations have compromised lawful intercept systems, exposed metadata for millions of users, and disrupted essential services. Recent activities observed by Darktrace in a European telecommunications organization included dynamic-link library sideloading and the use of legitimate software for stealth.
Salt Typhoon is identified as a significant cyber threat targeting global critical infrastructure.
The intrusion likely began with the exploitation of a Citrix NetScaler Gateway appliance in early July 2025. The attacker pivoted to Citrix Virtual Delivery Agent hosts in the client's Machine Creation Services subnet.
Initial access activities originated from an endpoint potentially associated with the SoftEther VPN service, suggesting infrastructure obfuscation. The threat actor delivered a backdoor, assessed as SNAPPYBEE, to multiple Citrix VDA hosts. This backdoor was delivered alongside legitimate executable files for antivirus software, using DLL sideloading techniques.
The backdoor communicated via LightNode VPS endpoints for command-and-control, utilizing both HTTP and an unidentified TCP-based protocol. This dual-channel setup aligns with Salt Typhoon's known use of non-standard protocols to evade detection.
The backdoor's HTTP communications involved POST requests with an Internet Explorer User-Agent header and specific Target URI patterns. One of the compromised endpoints contacted a domain associated with Salt Typhoon.
Darktrace's Cyber AI Analyst produced high-confidence detections during the early stages of the intrusion, covering both initial tooling and command-and-control activities. These detections were crucial in neutralizing the threat before it could escalate.
The Cyber AI Analyst autonomously investigated model alerts, discovering initial tooling and command-and-control events, and combining them into unified incidents. Darktrace assesses with moderate confidence that the observed activity aligns with Salt Typhoon's tactics, techniques, and procedures.
Organizations are urged to reassess their threat models, as Salt Typhoon highlights the evolving nature of nation-state cyber operations. Proactive defense strategies relying on behavioral anomaly detection are essential for addressing these threats effectively.
Based on reporting by GBHackers.




