dark-trace · Crawled Jul 25, 2026

Salty Much: Darktrace’s take on a recent Salt Typhoon intrusion

18 IoCs 2 Actors 1 Malware
Read original article ↗

AI Summary

Salt Typhoon, a China-linked advanced persistent threat (APT) group also known as Earth Estries or UNC2286, conducted a cyber espionage intrusion targeting a European telecommunications organization. The attack began with exploitation of CVE-2025-5777 in Citrix NetScaler Gateway appliances, followed by lateral movement and DLL sideloading using legitimate antivirus software to execute the SNAPPYBEE (Deed RAT) backdoor. Command-and-control communications were observed using suspicious domains and IPs, with activity detected and contained early by Darktrace’s AI-driven systems.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 18 extracted

Type Value Detail
IP 89[.]31[.]121[.]101 Details →
IP 38[.]54[.]63[.]75 Details →
IP 156[.]244[.]28[.]153 Details →
Domain aar[.]gandhibludtric[.]com Details →
SHA-1 b5367820cd32640a2d5e4c3a3c1ceedbbb715be2 Details →
Filename WINMM.dll Details →
Filename NortonLog.txt Details →
Filename 123.txt Details →
Filename 123.tar Details →
Filename pdc.exe Details →
Filename Dialog.dat Details →
Filename fltLib.dll Details →
Filename DisplayDialog.exe Details →
Filename DgApi.dll Details →
Filename dbindex.dat Details →
Filename 1.txt Details →
Filename imfsbDll.dll Details →
Filename imfsbSvc.exe Details →

MITRE ATT&CK TTPs 23 techniques