Salt Typhoon Targets European Telecom
bankinfosecurityAttack Began With Citrix NetScaler Gateway Compromise, Darktrace Said Akshaya Asokan (asokan_akshaya) • October 20, 2025

The Chinese cyberespionage hackers commonly tracked as Salt Typhoon haven't stopped their campaign against global telecoms, says managed threat detection firm Darktrace.
See Also: OnDemand | North Korea's Secret IT Army and How to Combat It
The first said Monday it spotted threat activity consistent with Salt Typhoon indicators in July hacking an European telecom.
Salt Typhoon - also tracked as Earth Estries, GhostEmperor and UNC2286 - is operated by a clutch of private hacking firms whose clients include multiple Chinese government agencies, according to analysis from earlier this year based on leaked data (see: Chinese Data Leak Reveals Salt Typhoon Contractors).
The group has made telecoms and other digital infrastructure a primary target. The group leapt into public awareness after hacking nine U.S. telecoms in a campaign that became public knowledge in ...
Copyright of this story solely belongs to bankinfosecurity . To see the full text click HERE

