Salty Much: Darktrace’s take on a recent Salt Typhoon intrusion
3w ago · dark-trace
Salt Typhoon, a China-linked advanced persistent threat (APT) group also known as Earth Estries or UNC2286, conducted a cyber espionage intrusion targeting a European telecommunications organization. The attack began with exploitation of CVE-2025-5777 in Citrix NetScaler Gateway appliances, followed by lateral movement and DLL sideloading using legitimate antivirus software to execute the SNAPPYBEE (Deed RAT) backdoor. Command-and-control communications were observed using suspicious domains and IPs, with activity detected and contained early by Darktrace’s AI-driven systems.
18 IoCs 2 Actors 1 Malware