Adversary Intelligence — 2026-05-16

Chinese APT Groups Expand Targets and Update Backdoor Arsenal

BLUFBehavioral sequencing, not indicator matching, is now the only durable detection surface against these China-nexus actors, whose stable tradecraft and adaptive reentry render IoC-driven defenses structurally insufficient for energy and finance networks.

Bitdefender reported, at moderate-to-high confidence, a Salt Typhoon intrusion against an Azerbaijani oil and gas company from December 2025 through late February 2026, initiated through Microsoft Exchange ProxyNotShell exploitation and advancing through DLL-sideloaded deployments of Deed RAT and, following partial remediation, TernDoor. Darktrace separately attributed, at moderate confidence, a Twill Typhoon campaign targeting Asia-Pacific and Japan organizations from late September 2025 through at least April 2026, using infrastructure impersonating Yahoo and Apple content delivery networks. Affected hosts retrieved legitimate Windows binaries alongside malicious DLLs in a staged sequence to sideload an updated FDMTP backdoor, version 3.2.5.1, within trusted processes including the Windows ClickOnce engine and Visual Studio hosting binary. A finance-sector endpoint, per Darktrace, made repeated requests to attacker-controlled infrastructure over an 11-day window in April 2026.

Analysis
Salt Typhoon's return to the Azerbaijani energy host with TernDoor after defenders removed Deed RAT confirms adaptive persistence: the actor absorbed the defensive response and reentered rather than abandoning the environment. Bitdefender's re-attribution from FamousSparrow collapses what appeared as two actors into one sustained campaign. The targeting shift tracks Azerbaijan's elevated role as a European gas transit corridor after Russia's Ukraine transit agreement lapsed. Per Darktrace alone, Twill Typhoon's execution sequence held stable across six months while infrastructure and payload hashes rotated, making behavioral sequencing the primary durable detection surface. The FDMTP tradecraft and DLL sideloading are shared across several China-nexus clusters, leaving open that a distinct actor operated under Twill Typhoon signatures to complicate forensic attribution.
5 sources
  1. Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns - SecurityWeek
  2. Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor - Darktrace
  3. Twill Typhoon used legitimate Windows tools, DLL sideloading, FDMTP backdoor in APAC espionage campaign - Industrial Cyber
  4. Hackers used faked Apple & Yahoo infrastructure to hide malware - AppleInsider
  5. Mustang Panda Linked to FDMTP Backdoor in Asia-Pacific Espionage - Infosecurity Magazine

View in full brief →

UNCLASSIFIED // OPEN SOURCE