logo

Salt Typhoon used dozens of domains, going back five years. Did you visit one?

ID: 663e21af-d9fa-55fc-adc0-223dacffb83b

STIX ID: report--663e21af-d9fa-55fc-adc0-223dacffb83b

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-09-08

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Security researchers (Silent Push) identified 45 domains, many previously unreported, linked to the China-backed espionage group Salt Typhoon/UNC4841; these domains appear to form C2 infrastructure used for long-term access dating back to 2020 and are associated with prior telecom intrusions and exploitation of a Barracuda ESG vulnerability. The report highlights fake registrant personas, shared registration patterns, low-density IPs in DNS A records, and recommends defenders check telemetry and historical logs to hunt and remove this persistent espionage infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.