Salt Typhoon used dozens of domains, going back five years. Did you visit one?
ID: 663e21af-d9fa-55fc-adc0-223dacffb83b
STIX ID: report--663e21af-d9fa-55fc-adc0-223dacffb83b
Feed Name: The Register (Security)
Security researchers (Silent Push) identified 45 domains, many previously unreported, linked to the China-backed espionage group Salt Typhoon/UNC4841; these domains appear to form C2 infrastructure used for long-term access dating back to 2020 and are associated with prior telecom intrusions and exploitation of a Barracuda ESG vulnerability. The report highlights fake registrant personas, shared registration patterns, low-density IPs in DNS A records, and recommends defenders check telemetry and historical logs to hunt and remove this persistent espionage infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
