Darktrace published an intrusion analysis on Darktrace documenting Salt Typhoon (also tracked as Earth Estries, GhostEmperor, UNC2286) activity against a European telecommunications organization in July 2025. Salt Typhoon has been active since at least 2019, targeting telecoms, energy networks, and government systems across more than 80 countries — primarily the United States — using custom malware, exploitation of edge devices (Ivanti, Fortinet, Cisco), and long-term persistence to expose lawful intercept systems and exfiltrate user metadata. The EMEA-targeting intrusion documented here was detected and contained at an early stage via behavioral anomaly detection.
Initial Access: CVE-2025-5777 Citrix NetScaler Gateway and SoftEther VPN Infrastructure Obfuscation
The intrusion began in the first week of July 2025 with exploitation of CVE-2025-5777, a vulnerability affecting Citrix NetScaler Gateway appliances. From the NetScaler foothold, the actor pivoted to Citrix Virtual Delivery Agent (VDA) hosts within the client's Machine Creation Services (MCS) subnet. Initial access activity originated from an endpoint associated with the SoftEther VPN service (MITRE T1665 — Hide Infrastructure), indicating deliberate obfuscation of the true origin infrastructure from the outset of the operation.
SNAPPYBEE/Deed RAT Delivery via Antivirus DLL Sideloading: Norton, Bkav, and IObit
The threat actor delivered a backdoor assessed with high confidence as SNAPPYBEE (also known as Deed RAT) to multiple Citrix VDA hosts. The payload was delivered as a malicious DLL alongside legitimate executables from three antivirus products: Norton Antivirus, Bkav Antivirus, and IObit Malware Fighter. DLL sideloading (MITRE T1574.001) caused the legitimate AV processes to load the malicious DLL, executing the SNAPPYBEE payload under a trusted process context and bypassing signature-based controls. Observed sideloaded artifacts from staging server 89.31.121[.]101:443 include WINMM.dll, NortonLog.txt, imfsbDll.dll/imfsbSvc.exe (IObit), DgApi.dll/DisplayDialog.exe, fltLib.dll, and dbindex.dat.
Dual-Channel C2: LightNode VPS, IE User-Agent HTTP POST, and Confirmed Salt Typhoon Domain
SNAPPYBEE communicated with LightNode VPS endpoints over two channels: HTTP POST requests using an Internet Explorer User-Agent header with target URI patterns matching /17ABE7F017ABE7F0, and an unidentified TCP-based protocol on non-standard ports (T1095/T1571). One confirmed C2 host, aar.gandhibludtric[.]com (38.54.63[.]75), had been independently linked to Salt Typhoon in prior reporting. A second C2 candidate, 156.244.28[.]153, was associated with the /17ABE7F017ABE7F0 URI pattern. Darktrace's behavioral AI detections identified both the DLL sideloading activity and the dual C2 channel during the intrusion's early stages, enabling containment before lateral movement or data exfiltration occurred.