Salt Typhoon Using Zero-Day Exploits and DLL Sideloading Techniques to Attack Organizations

Salt Typhoon, a China-linked advanced persistent threat (APT) group active since 2019, has emerged as one of the most sophisticated cyber espionage operations targeting global critical infrastructure.

Also tracked as Earth Estries, GhostEmperor, and UNC2286, the group has conducted high-impact campaigns against telecommunications providers, energy networks, and government systems across more than 80 countries.

The threat actor leverages zero-day exploits in edge devices including Ivanti, Fortinet, and Cisco appliances to establish initial access, while employing DLL sideloading techniques to maintain stealth and evade traditional signature-based detection mechanisms.

Recent intrusions demonstrate an alarming capability to compromise lawful intercept systems and exfiltrate metadata affecting millions of users.

The group’s operations blend intelligence collection with geopolitical influence, exposing the strategic nature of state-sponsored cyber campaigns.

DarkTrace analysts identified early-stage intrusion activity in a European telecommunications organization during July 2025, observing tactics consistent with Salt Typhoon’s known procedures.

The intrusion began with exploitation of a Citrix NetScaler Gateway appliance, allowing the threat actor to pivot to Citrix Virtual Delivery Agent hosts within the organization’s Machine Creation Services subnet.

Initial access originated from infrastructure potentially associated with the SoftEther VPN service, demonstrating infrastructure obfuscation from the outset.

DLL Sideloading and Persistence Mechanisms

The technical sophistication of Salt Typhoon’s operations becomes evident through their systematic abuse of legitimate software for malicious purposes.

DarkTrace researchers observed the delivery of SNAPPYBEE backdoor, also known as Deed RAT, to multiple internal endpoints as DLL files accompanied by legitimate executable files from trusted antivirus solutions.

The threat actor specifically targeted Norton Antivirus, Bkav Antivirus, and IObit Malware Fighter executables to facilitate DLL side-loading operations.

This technique enabled the group to execute malicious payloads under the guise of trusted security software, effectively bypassing traditional security controls.

The backdoor established command-and-control communications through LightNode VPS endpoints, utilizing both HTTP and an unidentified TCP-based protocol.

HTTP communications featured POST requests with distinctive URI patterns such as “/17ABE7F017ABE7F0”, connecting to the domain aar.gandhibludtric[.]com (38.54.63[.]75), recently linked to Salt Typhoon infrastructure.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago