Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagetelecommunications-sector-threatinitial-access-methodlateral-movement-method

Salt Typhoon Intrusion Attempt on European Telecommunications Provider via Citrix NetScaler Exploit

Updated 3mo agoFirst seen Oct 21, 20256 sources

Salt Typhoon, a Chinese state-linked advanced persistent threat (APT) group, attempted to infiltrate a European telecommunications organization by exploiting a vulnerability in a Citrix NetScaler Gateway appliance. The attack was first detected by Darktrace in July 2025, when threat activity consistent with Salt Typhoon’s known tactics, techniques, and procedures (TTPs) was observed. The group, also known as Earth Estries, GhostEmperor, and UNC2286, has a history of targeting telecoms and digital infrastructure globally, with previous campaigns against U.S. telecoms and ongoing interest in European targets. Initial access was achieved through the exploitation of the Citrix NetScaler Gateway, a method frequently used by Salt Typhoon to compromise network equipment. After breaching the gateway, the attackers moved laterally within the organization, targeting Citrix Virtual Delivery Agent hosts in the Machine Creation Services (MCS) subnet. The group deployed the SNAPPYBEE (also known as Deed RAT) backdoor, a tool commonly shared among Chinese APT groups, to establish command and control (C2) within the compromised environment. The C2 infrastructure utilized LightNode VPS endpoints and communicated over both HTTP and an unidentified TCP-based protocol, demonstrating the group’s use of non-standard and layered protocols to evade detection. To maintain stealth and persistence, Salt Typhoon employed DLL sideloading techniques, delivering malicious DLLs alongside legitimate antivirus executables such as Norton Antivirus, Bkav Antivirus, and IObit Malware Fighter. This allowed the attackers to execute their payloads under the guise of trusted software, bypassing traditional security controls. The group’s tactics included abusing legitimate software for stealth and execution, a hallmark of their operations. Darktrace analysts noted that the pattern of activity closely matched Salt Typhoon’s previous campaigns, reinforcing attribution to the group. The intrusion was detected before the attackers could achieve deeper compromise or exfiltrate sensitive data, highlighting the importance of proactive threat detection. The incident underscores the persistent threat posed by Chinese cyberespionage actors to the telecommunications sector, particularly through the exploitation of known vulnerabilities in widely used network appliances. The Five Eyes intelligence alliance and other international partners have previously warned about Salt Typhoon’s global targeting of communications infrastructure. The group’s operations are believed to be conducted by private hacking firms contracted by Chinese government agencies, as revealed by earlier data leaks. The attempted breach demonstrates the evolving sophistication of state-sponsored cyber operations and the need for robust security measures in critical infrastructure sectors. The use of advanced lateral movement, stealthy persistence mechanisms, and shared malware tools reflects the group’s technical capabilities. The incident also highlights the value of threat intelligence sharing and rapid response in mitigating nation-state cyber threats. Ongoing monitoring and patching of network equipment vulnerabilities remain essential defenses against such targeted attacks. The European telecom’s timely detection and response prevented further escalation and potential operational impact. This event adds to the growing body of evidence regarding Salt Typhoon’s focus on global telecommunications espionage.

Share:
Salt Typhoon Intrusion Attempt on European Telecommunications Provider via Citrix NetScaler Exploit
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Oct 20, 20258mo ago

Darktrace publicly reports Salt Typhoon's European telecom targeting

Multiple outlets reported on 2025-10-20 and 2025-10-21 that Darktrace had disclosed Salt Typhoon's July 2025 targeting of a European telecom. The reporting tied the activity to the China-linked espionage group also known as Earth Estries, GhostEmperor, and UNC2286.

Jul 1, 20251y ago

Darktrace detects and disrupts the European telecom intrusion

Darktrace observed the July 2025 Salt Typhoon activity against the European telecom and reported that the attack was detected and stopped early. The company said the attackers established dual-channel command-and-control infrastructure using virtual private servers.

Salt Typhoon targets a European telecom via Citrix NetScaler

In July 2025, Salt Typhoon attempted to compromise a European telecommunications organization, likely by exploiting a Citrix NetScaler Gateway vulnerability. The intrusion involved living-off-the-land techniques, including DLL side-loading through legitimate antivirus software, and deployment of the SNAPPYBEE backdoor.

Citrix patches NetScaler flaws CVE-2025-5777 and CVE-2025-6543

Citrix released patches in July 2025 for two NetScaler Gateway vulnerabilities, CVE-2025-5777 and CVE-2025-6543. The flaws could enable multifactor authentication bypass and session hijacking and were later linked to Salt Typhoon activity.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
16 linked
DarktraceCitrix SystemsSalt TyphoonSymantec, Inc.Verizon CommunicationsSoftEther CorporationfbiCanada’s Cyber CentreAT&TBlack DuckPeople's Republic of ChinaT-Mobile USCisco SystemsPalo Alto NetworksIvantiFive Eyes
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Salt Typhoon Intrusion Attempt on European Telecommunications Provider via Citrix NetScaler Exploit | Mallory