EPISODE · May 14, 2026 · 0 MIN
Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns
from Security Stuff · host Trace3
Chinese state-sponsored hacking groups Salt Typhoon and Twill Typhoon have been conducting sustained campaigns with updated tools and expanded targets between late 2025 and early 2026. Salt Typhoon notably shifted focus to target an Azerbaijani oil and gas company, exploiting the country's growing importance in European energy security following disruptions in Russian gas transit and the Strait of Hormuz. Both groups demonstrated persistent access techniques, with Salt Typhoon repeatedly deploying backdoors like Deed RAT and TernDoor over multiple months, and Twill Typhoon using a new modular RAT framework disguised through legitimate services across the Asia-Pacific region.
Embed this episode
What this episode covers
Chinese state-sponsored hacking groups Salt Typhoon and Twill Typhoon have been conducting sustained campaigns with updated tools and expanded targets between late 2025 and early 2026. Salt Typhoon notably shifted focus to target an Azerbaijani oil and gas company, exploiting the country's growing importance in European energy security following disruptions in Russian gas transit and the Strait of Hormuz. Both groups demonstrated persistent access techniques, with Salt Typhoon repeatedly depl...
NOW PLAYING
Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.