logo

Salt Typhoon's surge extends far beyond US telcos

ID: 4a253405-09d4-509f-bdc0-2cd0d25d6f97

STIX ID: report--4a253405-09d4-509f-bdc0-2cd0d25d6f97

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-11-27

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Trend Micro reports that the China-linked APT "Salt Typhoon" (Earth Estries) has conducted prolonged, global cyber-espionage campaigns since 2020 against telcos, governments, consultants, NGOs and suppliers in over 20 organizations and many countries. The attackers exploit public-facing CVEs (including Ivanti, Fortinet, Sophos, and Microsoft Exchange flaws), use living-off-the-land tools (WMIC, PsExec) for lateral movement, and deploy malware such as SnappyBee/Deed RAT, the Demodex rootkit, and a newly observed GhostSpider backdoor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.