logo

Salt Typhoon hackers backdoor telcos with new GhostSpider malware

ID: 430aef7b-03f9-57af-ae45-24ce5547a72e

STIX ID: report--430aef7b-03f9-57af-ae45-24ce5547a72e

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-11-25

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Salt Typhoon (aka UNC2286) is a sophisticated Chinese state‑sponsored APT observed by Trend Micro mounting global espionage campaigns against telecommunications and government targets using a modular in‑memory backdoor called GhostSpider, multiple additional backdoors/rootkits (Masol RAT, Demodex, SnappyBee), and exploitation of public‑facing CVEs (e.g., Ivanti, Fortinet, Sophos, Microsoft Exchange) for initial access; the report documents active breaches, large-scale impact (including intercepted communications of U.S. officials), and a multi-stage, stealthy toolchain enabling prolonged access and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.