Salt Typhoon Targets European Telecom via Citrix Exploit

21 Oct 2025

In July 2025, a European telecommunications organization was targeted by Salt Typhoon, a cyber espionage group with links to China. The attackers exploited a Citrix NetScaler Gateway appliance to gain initial access, allowing them to penetrate deeper into the organization’s infrastructure.

Attack Methodology

Salt Typhoon's operation involved compromising Citrix Virtual Delivery Agent (VDA) hosts located in the client's Machine Creation Services (MCS) subnet. They utilized DLL side-loading alongside legitimate antivirus executables such as Norton Antivirus, Bkav Antivirus, and IObit Malware Fighter to obscure their origins. The goal was to deliver Snappybee (also known as Deed RAT), suspected to be the successor of ShadowPad.

The malware established communication with an external server (aar.gandhibludtric[.]com) using HTTP and a TCP-based protocol. This precise technique underscores Salt Typhoon's capability to maintain stealth in their activities.

Defense and Response

Darktrace, a cybersecurity firm, identified and managed to mitigate the intrusion before significant escalation could occur. The persistent operations of Salt Typhoon, active since 2019, have targeted over 80 countries, making telecommunications providers, energy networks, and government systems their focus.

This development signals an ongoing threat from advanced persistent threat groups exploiting edge-device vulnerabilities. Organizations need to bolster their cybersecurity measures to prevent such intrusions effectively.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6180849
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1183857
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
453263
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
449465
downloads

News and reviews for Desktop Windows

Frogwares Delays Sinking City 2 to 2026

Frogwares shifts Sinking City 2 release to 2026 amid Ukraine war challenges.

Read more

Microsoft Fixes WinRE Glitch in Windows 11 Patch

Microsoft's WinRE patch KB5070773 for Windows 11 users, fixing USB input issues caused by the October update.

Read more

Lumma Malware Targets Windows for Data Theft

Lumma, a sophisticated malware, resurfaces targeting Windows systems for credential theft via Malware-as-a-Service. Impacting global cybersecurity.

Read more

Jackbox Party Pack 11 Launches With Five New Games

Jackbox launches Party Pack 11 on 2023-10-23 with five original games. Includes fantasy trivia and social deduction options.

Read more

Guide Reveals Top Outfits in Bloodlines 2

Discover how clan powers unlock outfits in Bloodlines 2 and influence NPC interactions.

Read more

Over 500 Games at Steam Next Fest Use Generative AI

504 Steam Next Fest demos disclosed using Generative AI for development, impacting game creation roles.

Read more

SWTOR Update 7.8 Enhances Outer Rim Gameplay

SWTOR update 7.8 brings dynamic encounters to Dantooine, adding new challenges and player rewards.

Read more

Reveals Bloodlines 2 Main Mission List

Bloodlines 2 unveils its main missions, featuring 21 quests in a mysterious RPG setting. Side quests to follow.

Read more

Salt Typhoon Targets European Telecom via Citrix Exploit

Salt Typhoon cyber group attacked a European telecom in July 2025, exploiting Citrix devices.

Read more

N++ Update Adds Challenging Levels for 10th Anniversary

Metanet celebrates N++'s 10th anniversary with the free Ten++ update, adding new levels and features to the platformer game.

Read more