Salt Typhoon hackers backdoor telcos with new GhostSpider malware
ID: 430aef7b-03f9-57af-ae45-24ce5547a72e
STIX ID: report--430aef7b-03f9-57af-ae45-24ce5547a72e
Feed Name: Bleeping Computer
Salt Typhoon (aka UNC2286) is a sophisticated Chinese state‑sponsored APT observed by Trend Micro mounting global espionage campaigns against telecommunications and government targets using a modular in‑memory backdoor called GhostSpider, multiple additional backdoors/rootkits (Masol RAT, Demodex, SnappyBee), and exploitation of public‑facing CVEs (e.g., Ivanti, Fortinet, Sophos, Microsoft Exchange) for initial access; the report documents active breaches, large-scale impact (including intercepted communications of U.S. officials), and a multi-stage, stealthy toolchain enabling prolonged access and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
