Salt Typhoon Builds Out Malware Arsenal With GhostSpider
ID: 3c92321b-d440-5a2b-ac70-163de017d518
STIX ID: report--3c92321b-d440-5a2b-ac70-163de017d518
Feed Name: Dark Reading
Salt Typhoon (aka Earth Estries / FamousSparrow / UNC2286) is a sophisticated Chinese APT that has performed long-term espionage against governments, telcos, ISPs and related organizations across multiple continents; since 2023 it has compromised more than 20 organizations using modular backdoors (GhostSpider, Masol RAT, SnappyBee), a rootkit (Demodex), and by exploiting n-day vulnerabilities (notably CVE-2024-48788, CVE-2022-3236 and Microsoft Exchange ProxyLogon flaws) to gain access, persistence, and move laterally.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
