Chinese APT Groups Expand Targets and Update Backdoor Arsenal
Bitdefender reported, at moderate-to-high confidence, a
Salt Typhoon's return to the Azerbaijani energy host with TernDoor after defenders removed Deed RAT confirms adaptive persistence: the actor absorbed the defensive response and reentered rather than abandoning the environment. Bitdefender's re-attribution from FamousSparrow collapses what appeared as two actors into one sustained campaign. The targeting shift tracks Azerbaijan's elevated role as a European gas transit corridor after Russia's Ukraine transit agreement lapsed. Per Darktrace alone, Twill Typhoon's execution sequence held stable across six months while infrastructure and payload hashes rotated, making behavioral sequencing the primary durable detection surface. The FDMTP tradecraft and DLL sideloading are shared across several China-nexus clusters, leaving open that a distinct actor operated under Twill Typhoon signatures to complicate forensic attribution.
5 sources
- Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns -
SecurityWeek - Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor -
Darktrace - Twill Typhoon used legitimate Windows tools, DLL sideloading, FDMTP backdoor in APAC espionage campaign -
Industrial Cyber - Hackers used faked Apple & Yahoo infrastructure to hide malware -
AppleInsider - Mustang Panda Linked to FDMTP Backdoor in Asia-Pacific Espionage -
Infosecurity Magazine