China’s Salt Typhoon Strikes Again: European Telecom Hacked via Citrix Exploit
China-linked Salt Typhoon, also known as Earth Estries and other names, breached a European telecom in July 2025 using a Citrix NetScaler Gateway exploit. This cyberespionage escapade underscores the need for advanced threat detection, as the group’s stealthy tactics leave traditional security measures feeling like they’ve been caught in a tech typhoon.

Hot Take:
Watch out folks, it seems the Salt Typhoon has turned into a full-blown hurricane! Not only are they hitting European telecoms like a caffeine-fueled teenager on a gaming spree, but they’re also making Citrix their go-to battering ram. The moral of the story? If your cybersecurity strategy involves just crossing your fingers, you might want to rethink that. And perhaps consider a good raincoat because it’s storming out there!
Key Points:
- China-linked Salt Typhoon targeted a European telecom via Citrix exploit.
- The attack is part of a broader campaign targeting global telecoms over the past 1-2 years.
- Sophisticated techniques like DLL sideloading and VPN obfuscation were used.
- Darktrace’s AI detected and mitigated the attack before it could escalate.
- The incident highlights the need for behavior-based detection over traditional methods.
