JumbledPath — Malware Profile
JumbledPath is a custom-built utility written in GO that has been used by Salt Typhoon since at least 2024 for packet capture on remote Cisco devices. JumbledPath is compiled as an ELF binary using x86-64 architecture which makes it potentially useable across Linux operating systems and network devices from multiple vendors.
MITRE ATT&CK techniques (6)
- T1040 Network Sniffing
- T1104 Multi-Stage Channels
- T1560 Archive Collected Data
- T1665 Hide Infrastructure
- T1685 Disable or Modify Tools
- T1685.006 Clear Linux or Mac System Logs