Threat hunters have found a collection of hitherto unreported domains, some dating back to May 2020, that are connected to UNC4841 and Salt Typhoon, two threat actors with ties to China.
According to a recent investigation provided to The Hacker News, Silent Push stated that the domains have been registered for a number of years, with the earliest registration activity taking place in May 2020. This further supports the idea that the 2024 Salt Typhoon attacks were not the group’s first action.
The 45 domains of the identified infrastructure have also been found to share some overlap with UNC4841, another hacker group associated with China that is most famous for exploiting a security flaw in Barracuda Email Security Gateway (ESG) appliances in a zero-day attack (CVE-2023-2868, CVSS score: 9.8).
Targeting U.S. telecom service providers, Salt Typhoon, which has been active since 2019, garnered a lot of attention last year. Similar to operations monitored as Earth Estries, the threat cluster is thought to be run by China’s Ministry of State Security (MSS) read more about 45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
