惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
博客园 - Franky
博客园 - 三生石上(FineUI控件)
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
人人都是产品经理
人人都是产品经理
博客园 - 【当耐特】
L
LangChain Blog
Stack Overflow Blog
Stack Overflow Blog
H
Help Net Security
爱范儿
爱范儿
罗磊的独立博客
博客园_首页
美团技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
V
Visual Studio Blog
T
Tailwind CSS Blog

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Update: Salt Typhoon
Intel 471 · 2025-08-08 · via Intel 471 Blog

Threat Summary

UPDATE 08/05/2025: During the last year, Salt Typhoon operations have prominently featured the exploitation of vulnerabilities in Cisco's IOS XE software, notably CVE-2023-20198 and CVE-2023-20273, to gain unauthorized access to network devices. These attacks have led to the compromise of a number of entities including major telecommunications providers in the United States, Canada, and South Africa, with the group breaching the satellite communications firm Viasat in early 2025 for instance. Beyond exploiting known vulnerabilities, Salt Typhoon also has a history of employing sophisticated techniques tied to malware that include deploying trojanized payloads for downloading additional tools, exfiltrating data or executing remote commands on a victim’s system. Furthermore, techniques that have been observed also involve the capture and exfiltration of data that can range from sensitive credentials, session tokens and information pertaining to the victim or the victim’s system. With these tactics, attackers are able to laterally move across networks, and leverage existing network tools and protocols to conduct malicious activities without triggering security alarms. The group's strategic focus on telecommunications infrastructure allows for extensive intelligence collection, including the interception of communications and monitoring of law enforcement activities, posing significant risks to national security.


Salt Typhoon is an APT threat actor that has most recently and publicly breached the systems of major United States based telecommunication providers (specifically ISPs) in September/October of 2023 - the networks affected by the breach included Verizon Communications, AT&T and Lumen Technologies. Considered to be an extremely damaging cyber espionage campaign, the threat actors claimed to have been entrenched in their systems for 'months'. The intrusion gave attackers access to proprietary intelligence and law enforcement data, exploiting systems used for what is understood as lawful wiretapping. The threat actor Salt Typhoon (also known as GhostEmperor, Famous Sparrow or UNC2286), has been active since 2020 and is operated by the Chinese Government to conduct cyber espionage campaigns against targets in North America, Southeast Asia, and Europe. It is also worthy to note that the industries that the threat actor has been observed to attack include telecommunications, government and information technology.


With the evolving cyber threat from entities based in China, this highly damaging attack on U.S. wiretap systems by Salt Typhoon, and the likely impending release of the techniques, tactics and procedures involved in the intrusion, it is important to ascertain and keep track of any information involving this threat group as more data is released.

TITAN References:

TITAN Spot Report: September 26, 2024
TITAN Spot Report: October 5, 2024

TITAN Intelligence Bulletin: July 3, 2025

TITAN Finished Intelligence Report: July 23, 2025

Get your FREE Community Account today on the HUNTER Platform and get access to behavioral threat hunting content for your SIEM, EDR, NDR, and XDR platforms!

Salt Typhoon Hunt Collection

ACCESS HUNT COLLECTION

Suspicious Scheduled Task Created - Execution Details Contains Scripting Reference

ACCESS HUNT PACKAGE

Single-Character Named Files Used for Execution

ACCESS HUNT PACKAGE


CURL/WGET Download and Execute - Potential Payload Download Followed by Execution

ACCESS HUNT PACKAGE

ACCESS HUNT PACKAGE

Suspicious BITS Activity

ACCESS HUNT PACKAGE

Single Character Batch Script File Executed on Endpoint

ACCESS HUNT PACKAGE

User Account Creation in Cisco IOS

ACCESS HUNT PACKAGE

Execution BAT Script to Unpack Payload

ACCESS HUNT PACKAGE

CertUtil File Download

ACCESS HUNT PACKAGE

DLL and EXE File Written in Same Directory in Short Period - Potential DLL Write for DLL Side Loading

ACCESS HUNT PACKAGE

Base64 Encoded Command Execution

ACCESS HUNT PACKAGE

Dump LSASS via comsvcs DLL

ACCESS HUNT PACKAGE

Potential Impacket wmiexec Module Command Execution

ACCESS HUNT PACKAGE

ACCESS HUNT PACKAGE

Potentially Abnormal Parent Process for cmd.exe or regedit.exe

ACCESS HUNT PACKAGE

DLL Dropped in ProgramData Directory - Possible Cobalt Strike Activity

ACCESS HUNT PACKAGE

Bitsadmin Downloading Payloads from Github

ACCESS HUNT PACKAGE

Excessive Windows Discovery CommandLine Arguments - Potential Malware Installation

ACCESS HUNT PACKAGE

WDigest Downgrade Attack - Registry Key Modification

ACCESS HUNT PACKAGE