Notorious Chinese hacking group Salt Typhoon found lurking in European comms networks
- Notorious hacking group Salt Typhoon has likely been targeting Telecom orgs
- Researchers identified tactics previously used by the group
- Salt Typhoon breached up to 8 US telecom networks in a huge cyber-espionage campaign
Notorious Chinese hacking group Salt Typhoon has been once again linked to intrusions against telecommunications firms – this time in Europe.
A new report from Darktrace claims the group has been observed, “targeting global infrastructure using stealthy techniques such as DLL sideloading and zero-day exploits.”
The early stage intrusion activity detected mirrors previous Salt Typhoon tactics, such as the prolific attacks on up to 8 different telecom organizations in a far reaching and potent multi-year campaign which resulted in the group stealing information from millions of American telecom customers using a high severity Cisco flaw to gain access and eventually collect traffic from the networks devices were connected to.
DLL side-loading
In the latest incident, Darktrace assessed with moderate confidence that Salt Typhoon abused legitimate tools with stealth and persistence – exploiting a Citrix NetScaler Gateway appliance to obtain initial access.
From there, the criminals deployed Snappybee malware, also known as Deed RAT, which is launched using a technique called DLL side-loading – another tactic commonly used by Chinese threat actors.
“The backdoor was delivered to these internal endpoints as a DLL alongside legitimate executable files for antivirus software such as Norton Antivirus, Bkav Antivirus, and IObit Malware Fighter,” Darktrace explained.
”This pattern of activity indicates that the attacker relied on DLL side-loading via legitimate antivirus software to execute their payloads. Salt Typhoon and similar groups have a history of employing this technique, enabling them to execute payloads under the guise of trusted software and bypassing traditional security controls.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Darktrace says the intrusion was identified and remediated before it could escalate beyond the early stages of attack – neutralizing the threat.
This highlights the vital importance of proactive, anomaly-based defense and detection above the more traditional signature-based methods, especially given the rise in persistent, state sponsored threat actors.

The best antivirus for all budgets
Notorious hacking group Salt Typhoon has likely been targeting Telecom orgs Researchers identified tactics previously used by the group Salt Typhoon breached up to 8 US telecom networks in a huge cyber-espionage campaign Notorious Chinese hacking group Salt Typhoon has been once again linked to intrusions against telecommunications firms –…
Recent Posts
- LG Promo Codes and Coupons for June 2026
- 30% Off Canon Promo Codes | June 2026
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023