Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Notorious Chinese hacking group Salt Typhoon found lurking in European comms networks

Tech Wavo by Tech Wavo
October 21, 2025
in Computers
0



  • Notorious hacking group Salt Typhoon has likely been targeting Telecom orgs
  • Researchers identified tactics previously used by the group
  • Salt Typhoon breached up to 8 US telecom networks in a huge cyber-espionage campaign

Notorious Chinese hacking group Salt Typhoon has been once again linked to intrusions against telecommunications firms – this time in Europe.

A new report from Darktrace claims the group has been observed, “targeting global infrastructure using stealthy techniques such as DLL sideloading and zero-day exploits.”

The early stage intrusion activity detected mirrors previous Salt Typhoon tactics, such as the prolific attacks on up to 8 different telecom organizations in a far reaching and potent multi-year campaign which resulted in the group stealing information from millions of American telecom customers using a high severity Cisco flaw to gain access and eventually collect traffic from the networks devices were connected to.


You may like

DLL side-loading

In the latest incident, Darktrace assessed with moderate confidence that Salt Typhoon abused legitimate tools with stealth and persistence – exploiting a Citrix NetScaler Gateway appliance to obtain initial access.

From there, the criminals deployed Snappybee malware, also known as Deed RAT, which is launched using a technique called DLL side-loading – another tactic commonly used by Chinese threat actors.

“The backdoor was delivered to these internal endpoints as a DLL alongside legitimate executable files for antivirus software such as Norton Antivirus, Bkav Antivirus, and IObit Malware Fighter,” Darktrace explained.

”This pattern of activity indicates that the attacker relied on DLL side-loading via legitimate antivirus software to execute their payloads. Salt Typhoon and similar groups have a history of employing this technique, enabling them to execute payloads under the guise of trusted software and bypassing traditional security controls.”

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Darktrace says the intrusion was identified and remediated before it could escalate beyond the early stages of attack – neutralizing the threat.

This highlights the vital importance of proactive, anomaly-based defense and detection above the more traditional signature-based methods, especially given the rise in persistent, state sponsored threat actors.

Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons
Previous Post

iPad Pro M5 review: Speed boost

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Notorious Chinese hacking group Salt Typhoon found lurking in European comms networks

by Tech Wavo
October 21, 2025
0
Jaguar Land Rover and Asahi finally set to restart some production following cyberattacks
Computers

Notorious hacking group Salt Typhoon has likely been targeting Telecom orgsResearchers identified tactics previously used by the groupSalt Typhoon breached...

Read more

iPad Pro M5 review: Speed boost

by Tech Wavo
October 21, 2025
0
iPad Pro M5 review: Speed boost
Computers

Apple is back with the latest version of the iPad Pro, and like the iPad Air earlier this year the...

Read more

X is testing a pay-per-use pricing model for its API

by Tech Wavo
October 21, 2025
0
X splits Verified Organizations into ‘Premium Business’ and ‘Premium Organizations’
Computers

Two years after revamping its developer programs and pricing, X is expanding the closed beta of a pay-per-use plan for...

Read more

I tried watchOS 26’s Workout Buddy but had to turn it off — here’s why

by Tech Wavo
October 21, 2025
0
I tried watchOS 26’s Workout Buddy but had to turn it off — here’s why
Computers

I work out a lot, so I like to know how well I’m doing and how much progress I’m making...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock