Salt Typhoon

Salt Typhoon APT Focuses on Global Telecom and Energy Industries, According to Darktrace

Cybersecurity research firm Darktrace has issued a report highlighting the ongoing threat posed by a state-sponsored group known as Salt Typhoon. This Advanced Persistent Threat (APT) group, suspected to be linked to the People’s Republic of China (PRC), continues to discover innovative methods to infiltrate critical infrastructure across the globe.…

Read MoreSalt Typhoon APT Focuses on Global Telecom and Energy Industries, According to Darktrace

Salt Typhoon Strikes European Telecom Sector

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Darktrace Reports on Compromise of Citrix NetScaler Gateway Akshaya Asokan (asokan_akshaya) • October 20, 2025 Image: Shutterstock Recent reports from the managed threat detection firm Darktrace indicate that a persistent campaign by the Chinese cyber espionage group known as Salt Typhoon continues…

Read MoreSalt Typhoon Strikes European Telecom Sector

Hackers Exploit Citrix Vulnerability and Snappybee Malware to Compromise European Telecom Network

October 21, 2025Ravie LakshmananCyber Espionage / Network Security A European telecommunications company has reportedly fallen victim to a cyber intrusion attributed to a threat actor associated with the China-linked group known as Salt Typhoon. This incident, as reported by Darktrace, took place during the first week of July 2025. Attackers…

Read MoreHackers Exploit Citrix Vulnerability and Snappybee Malware to Compromise European Telecom Network

Chinese Hackers Target T-Mobile and Other U.S. Telecoms in Extensive Espionage Operation

T-Mobile, a prominent U.S. telecommunications provider, has acknowledged being targeted by Chinese cyber threat actors aiming to infiltrate its systems to access sensitive data. The perpetrators, identified as Salt Typhoon, have been conducting a prolonged campaign focusing on extracting cellphone communications of individuals considered “high-value intelligence targets.” The extent of…

Read MoreChinese Hackers Target T-Mobile and Other U.S. Telecoms in Extensive Espionage Operation

T-Mobile Uncovers Network Intrusion Attempts from a Wireline Provider

T-Mobile Detects Intrusion Attempts, No Data Breach Confirmed Telecom giant T-Mobile recently announced that it has thwarted attempts by cyber actors to penetrate its networks in the past few weeks. Fortunately, the company confirmed that no sensitive customer data was accessed during these attempts. The intrusion efforts were traced back…

Read MoreT-Mobile Uncovers Network Intrusion Attempts from a Wireline Provider

Cisco Confirms Salt Typhoon’s Exploitation of CVE-2018-0171 to Attack U.S. Telecom Networks

Cisco has disclosed that a Chinese threat actor, identified as Salt Typhoon, successfully infiltrated major U.S. telecommunications companies by exploiting a known vulnerability labeled CVE-2018-0171 and utilizing stolen login credentials. This targeted operation reflects the sophisticated methods employed by adversaries focusing on critical infrastructure. According to Cisco Talos, the group…

Read MoreCisco Confirms Salt Typhoon’s Exploitation of CVE-2018-0171 to Attack U.S. Telecom Networks

Chinese APT Leverages BeyondTrust API Key to Infiltrate U.S. Treasury Systems and Access Sensitive Documents

The U.S. Treasury Department has reported a significant cybersecurity breach that has purportedly provided suspected Chinese threat actors with remote access to some computers and unclassified documents. This incident was publicly disclosed following a communication from BeyondTrust, a third-party software provider of the Treasury, on December 8, 2024, regarding unauthorized…

Read MoreChinese APT Leverages BeyondTrust API Key to Infiltrate U.S. Treasury Systems and Access Sensitive Documents

CISA Alerts on Two Actively Exploited Security Vulnerabilities in Adobe and Oracle Products

Recently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding two critical security flaws affecting Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM). This action stems from emerging evidence indicating active exploitation of these vulnerabilities. The newly added vulnerabilities are…

Read MoreCISA Alerts on Two Actively Exploited Security Vulnerabilities in Adobe and Oracle Products

RA World Ransomware Attack in South Asia Tied to Chinese Espionage Toolkit

A recent ransomware incident attributed to the RA World group has highlighted a troubling intersection between cyber espionage and financial extortion. In November 2024, an unnamed software and services company in Asia became the target of a sophisticated attack employing a malicious toolset closely associated with Chinese cyber espionage tactics.…

Read MoreRA World Ransomware Attack in South Asia Tied to Chinese Espionage Toolkit