Salt Typhoon's surge extends far beyond US telcos
ID: 4a253405-09d4-509f-bdc0-2cd0d25d6f97
STIX ID: report--4a253405-09d4-509f-bdc0-2cd0d25d6f97
Feed Name: The Register (Security)
Trend Micro reports that the China-linked APT "Salt Typhoon" (Earth Estries) has conducted prolonged, global cyber-espionage campaigns since 2020 against telcos, governments, consultants, NGOs and suppliers in over 20 organizations and many countries. The attackers exploit public-facing CVEs (including Ivanti, Fortinet, Sophos, and Microsoft Exchange flaws), use living-off-the-land tools (WMIC, PsExec) for lateral movement, and deploy malware such as SnappyBee/Deed RAT, the Demodex rootkit, and a newly observed GhostSpider backdoor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
