A cyber intrusion by China-linked group Salt Typhoon has been observed targeting global infrastructure via DLL sideloading.
The operation, identified by cybersecurity researchers, involves the exploitation of a Citrix NetScaler Gateway vulnerability, using advanced methods such as DLL sideloading and zero-day exploits.
Salt Typhoon, also known as Earth Estries, GhostEmperor and UNC2286, has been active since at least 2019, targeting critical sectors including telecommunications, energy and government systems across over 80 countries.
The group's activity has been observed in the United States, Europe, the Middle East and Africa, with a recent expansion of its reach.
No direct quote available.
Author's summary: Salt Typhoon targets global infrastructure.