Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    DeepMind Says Its AI Can Predict Hurricanes Earlier Than Everyone Else

    August 6, 2026

    Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery

    August 6, 2026

    The Download: Google’s AI shake-up and Meta’s rogue model

    August 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • DeepMind Says Its AI Can Predict Hurricanes Earlier Than Everyone Else
    • Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
    • The Download: Google’s AI shake-up and Meta’s rogue model
    • AI Hacks Are Bad. AI Worms and Viruses Will Be Worse
    • OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
    • OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
    • IEEE Course on Using AI to Modernize Power Grids
    • The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Suspected Salt Typhoon spies lurking in European telco • The Register
    Cybersecurity

    Suspected Salt Typhoon spies lurking in European telco • The Register

    kirklandc008@gmail.comBy kirklandc008@gmail.comOctober 21, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Suspected Salt Typhoon spies lurking in European telco • The Register
    Share
    Facebook Twitter LinkedIn Pinterest Email

    China’s Salt Typhoon gang appears to have successfully attacked a European telecommunications firm, according to security researchers at Darktrace.

    Salt Typhoon is an espionage gang linked to the People’s Republic of China that hacked America’s major telecommunications firms and stole metadata and other information belonging to “nearly every American,” according to a top FBI cyber official who spoke with The Register about the intrusions.

    The crew’s actions against US telcos came to light last year; however, it has been active since at least 2019 using tactics including exploiting edge devices, planting backdoors for stealthy, long-term network access, and stealing sensitive data across more than 80 countries.

    Today’s Darktrace report is the latest indication that Salt Typhoon is still actively targeting high-value networks and using stealthy techniques to avoid being caught.

    Citrix NetScaler Gateway for the initial access

    In the European telco intrusion described by Darktrace, the suspected spies exploited a buggy Citrix NetScaler Gateway appliance in the first week of July 2025 to gain access to the telecom’s network, according to the AI-powered security shop’s research team.

    While Darktrace doesn’t say which flaw(s) the suspected Chinese snoops abused to break in, Citrix had a busy summer patching security holes in its NetScaler Gateway products that had already been found and exploited by attackers.

    ”We didn’t confirm which one,” Nathaniel Jones, field CISO and VP of security and AI strategy at Darktrace, told The Register. “Given the timing, defenders were concurrently patching recent NetScaler flaws (e.g., CVE-2025-5349, CVE-2025-5777 in June).”

    In June, Citrix plugged CVE-2025-6543, a critical memory overflow flaw later reported as exploited in the wild, along with CVE-2025-5777, dubbed CitrixBleed 2, which was quickly added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.

    Then in August, Citrix patched these three: CVE-2025-7775 (dubbed CitrixBleed 3 by some), CVE-2025-7776, and CVE-2025-8424. Citrix rushed out patches for these CVEs in August, but miscreants spotted the vulnerabilities first.

    At the time, security maven Kevin Beaumont said CVE-2025-7775 had been exploited as a pre-auth RCE to plant web shells on unpatched boxes.

    CISA quickly added the bug to the KEV catalog, and the Dutch National Cyber Security Centre warned that mass exploitation was likely.

    ‘Infrastructure obfuscation from the outset’

    After compromising the Citrix NetScaler appliance, the Salt Typhoon miscreants pivoted to Citrix Virtual Delivery Agent (VDA) hosts in the client’s Machine Creation Services (MCS) subnet component. “Initial access activities in the intrusion originated from an endpoint potentially associated with the SoftEther VPN service, suggesting infrastructure obfuscation from the outset,” Darktrace’s threat hunters wrote in a Monday blog.

    Next, the suspected spies deployed a backdoor to multiple Citrix VDA hosts. “The actor progressed to backdooring multiple Citrix VDA hosts with SNAPPYBEE (aka Deed RAT) and establishing C2 when Darktrace flagged it,” Jones told us. “We feel confident it was remediated before the attack escalated. Thus, no dwell time.”

    Trend Micro researchers previously linked this modular backdoor to Salt Typhoon. Additionally, Darktrace says the intruders used DLL sideloading – also a favorite Salt Typhoon technique – to deliver the backdoor to these internal endpoints.

    DLL sideloading is a stealthy way to execute malware onto a victim’s machine and it involves tricking legitimate applications into loading a malicious Dynamic Link Library (DLL) file and then executing the payload. In this case, the attackers loaded the DLL alongside legitimate executable files for antivirus software, including Norton Antivirus, Bkav Antivirus, and IObit Malware Fighter, to help evade detection and execute the backdoor under the guise of trusted antivirus tools.

    Plus, the backdoor used LightNode VPS endpoints for C2, communicating over both HTTP and an unidentified TCP-based protocol, which is another technique Salt Typhoon uses to evade detection. Darktrace spotted the compromised endpoints pinging a particular C2 host, aar.gandhibludtric[.]com (38.54.63[.]75), which is one of the dozens of domains that threat intelligence firm Silent Push last month linked to Salt Typhoon.

    “Based on overlaps in TTPs, staging patterns, infrastructure, and malware, Darktrace assesses with moderate confidence that the observed activity was consistent with Salt Typhoon/Earth Estries (ALA GhostEmperor/UNC2286),” the researchers wrote.

    They also note that the vendor’s security platform identified and stopped the intrusion “before escalating beyond these early stages of the attack.” ®

    European lurking Register Salt spies Suspected telco Typhoon
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    The Download: reward hacking explained, and suspected Iranian cyberattacks

    August 3, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • DeepMind Says Its AI Can Predict Hurricanes Earlier Than Everyone Else
    • Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
    • The Download: Google’s AI shake-up and Meta’s rogue model
    • AI Hacks Are Bad. AI Worms and Viruses Will Be Worse
    • OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

    DeepMind Says Its AI Can Predict Hurricanes Earlier Than Everyone Else

    August 6, 2026

    Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery

    August 6, 2026

    The Download: Google’s AI shake-up and Meta’s rogue model

    August 6, 2026

    AI Hacks Are Bad. AI Worms and Viruses Will Be Worse

    August 6, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.