The Phaaaaaaaaantom of the Salt Typhoon is there, inside i-SOON

Daniel Schwalbe (Head of Investigations and CISO · Domain Tools)

BSidesSF 2026 · Day 1 · AMC Theatre 13

Overview

In this insightful talk, Daniel Schwalbe, Head of Investigations and CISO at DomainTools, unveils the intricate and evolving landscape of the Chinese state-sponsored threat actor, Salt Typhoon. Drawing heavily on the unprecedented 2024 i-SOON GitHub leak and extensive Passive DNS analysis, Schwalbe dissects the group's sophisticated operations, strategic objectives, and the burgeoning "industrialization" of state-backed cyber espionage through a contractor model. The presentation offers a critical look at how this threat actor targets vital infrastructure, particularly telecommunications and National Guard networks, and the innovative methods used by researchers to unmask their digital footprints.

Watch on YouTube

Key moments

  1. 0:00 Speaker introduction and talk overview
  2. 1:00 DomainTools Investigations' research-driven, community approach
  3. 2:20 Quick primer on Passive DNS for threat hunting
  4. 3:20 Technical explanation of Passive DNS cache miss collection
  5. 5:00 Key capabilities and power of Passive DNS for investigations

The Phaaaaaaaaantom of the Salt Typhoon is there, inside i-SOON

Speakers: Daniel Schwalbe

Conference: BSides SF

YouTube: https://www.youtube.com/watch?v=xfxRLd-GK58

Overview

In this insightful talk, Daniel Schwalbe, Head of Investigations and CISO at DomainTools, unveils the intricate and evolving landscape of the Chinese state-sponsored threat actor, Salt Typhoon. Drawing heavily on the unprecedented 2024 i-SOON GitHub leak and extensive Passive DNS analysis, Schwalbe dissects the group's sophisticated operations, strategic objectives, and the burgeoning "industrialization" of state-backed cyber espionage through a contractor model. The presentation offers a critical look at how this threat actor targets vital infrastructure, particularly telecommunications and National Guard networks, and the innovative methods used by researchers to unmask their digital footprints.

Schwalbe, a seasoned cybersecurity professional with over 25 years of experience and a self-proclaimed DNS nerd, emphasizes the talk's research-driven nature, highlighting DomainTools' commitment to community-focused intelligence beyond product promotion. The core message resonates with the urgent need for defenders to understand the adversary's evolving tactics, especially their reliance on a distributed network of front companies and contractors, and how to leverage powerful tools like Passive DNS for proactive threat hunting. This detailed exposition serves as a crucial resource for national security experts, critical infrastructure operators, and cybersecurity practitioners seeking to bolster their defenses against advanced persistent threats.

Background

▶ Watch: Speaker introduction and talk overview (0:00)

The talk delves into the activities of Salt Typhoon, an Advanced Persistent Threat (APT) group identified by Microsoft, also known by various other monikers such as Ghost Emperor, Famous Sparrow 2286, and Earth Krahang. This proliferation of names underscores a broader industry challenge in standardizing threat actor nomenclature, leading to unnecessary confusion. Salt Typhoon's primary mission is signals intelligence, characterized by long-term, deep-seated persistence, low-and-slow data exfiltration, and a focus on remaining undetected. Evidence strongly links this group to Chinese state-sponsored activities, primarily the Ministry of State Security (MSS) and, to a degree, the People's Liberation Army (PLA).

The group's Tactics, Techniques, and Procedures (TTPs) are notable for their emphasis on living off the land binaries (LOTL), favoring existing system tools like PowerShell to avoid detection, predominantly targeting Windows environments. They employ fake US personas for domain registration, mimic standard network operations to evade signature-based security products, and engage in credential harvesting via LSA's memory dumps. Unlike some other APTs, Salt Typhoon operates more as a campaign involving front companies, contractors, and hybrid firms, each with specialized expertise. Key targets include the US, UK, Taiwan, and the European Union, with confirmed breaches in telecommunications and US state National Guard networks. Their interest in telecoms extends to exploiting lawful intercept setups for illicit data extraction, while National Guard targeting aims to understand local command and control structures in response to disasters or conflicts. The MSS Chengdu bureaus appear to be a primary sponsor, focusing on foreign intelligence collection and cyber battlefield preparation, including dual-use capabilities for both espionage and potential infrastructure disruption. An overlap with the PLA is also noted, particularly concerning C4ISR (Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance) for wartime disruption.

A foundational element of the research presented is Passive DNS. Schwalbe provides a primer, explaining that while regular DNS queries resolve domain names to IP addresses, Passive DNS collects "cache miss" traffic between recursive DNS servers and authoritative name servers. This data, stored in a searchable database, offers unique investigative capabilities:

  • IP-to-domain resolution: Identifying all domains hosted on a given IP address.
  • Name server pivoting: Discovering all domains authoritative for a specific name server, crucial when adversaries manage their own DNS infrastructure.
  • Subdomain enumeration: Uncovering hidden or malicious subdomains.
  • Network neighborhood analysis: Identifying other suspicious domains within the same network block.
  • CNAME resolution: Tracing canonical names back to their original queries.
  • Regular expression searches: Pattern matching across any label of a Fully Qualified Domain Name (FQDN), useful for detecting Domain Generation Algorithm (DGA) patterns. These capabilities were instrumental in mapping Salt Typhoon's extensive infrastructure.

Key Findings

▶ Watch: DomainTools Investigations' research-driven, community approach (1:00)

The central revelation of the talk is the direct operational ties between i-SOON, a Chinese cybersecurity firm previously not considered state-linked, and the Salt Typhoon campaign. This connection was dramatically confirmed by the 2024 GitHub leak, an unprecedented trove of internal i-SOON documentation including meeting minutes, organizational charts, and even invoices. This leak provided an "inside look" into the structure and operational methods of a state-sponsored cyber espionage apparatus, revealing how seemingly legitimate companies function as fronts or contractors for the Chinese government.

Key findings derived from the leak and subsequent analysis include:

  • Infrastructure Registration: The leak provided granular details on how i-SOON and its affiliates register and manage their infrastructure, including domain procurement, weaponization, and the clear segregation of duties among different contracting entities.
  • Custom Malware and Toolchains: While Salt Typhoon heavily utilizes LOTL binaries, the leak offered insights into their custom malware deployments and shared toolchains, suggesting potential collaboration or replication among different APT groups.
  • Target Profiling: The documents corroborated and expanded upon existing knowledge of Salt Typhoon's target profiles, solidifying their focus on critical infrastructure and strategic intelligence.
  • Evolution from APT41: Salt Typhoon is likely a specialized subset of the formerly known APT41 (also called Double Dragon, Brass Typhoon). While APT41 focused on both espionage and financial gain across diverse industries, Salt Typhoon has a more concentrated mission: strategic espionage and potential cyber battlefield disruption, specifically targeting telecommunications backbones and critical infrastructure.
  • Industrialization of Cyber Espionage: The overarching theme is the "industrialization" of state-sponsored cyber operations. The Chinese government has shifted towards a contractor-enabled model, leveraging private firms like i-SOON. This approach offers efficiency, specialized expertise, and potentially better talent retention compared to purely military units, while also providing plausible deniability.
  • OSINT Validation: The leak served as a powerful validation for many existing Open Source Intelligence (OSINT) observations, confirming suspicions about the operational structure and affiliations of these groups. It also revealed new organizational details, such as regional tasking within the MSS Chengdu bureaus.
  • Individual Indictments: The research has direct links to US indictments, with individuals tied to i-SOON and Salt Typhoon now on the FBI's most wanted list. This demonstrates a rare public accountability measure and highlights how government agencies are leveraging such leaks for law enforcement actions.

The campaigns linked to i-SOON and Salt Typhoon include significant breaches:

  • 2024 Telecom Metadata Breach: Aimed at collecting signals intelligence and understanding US telecom command structures.
  • 2024 State National Guard Networks: Preparation of the battlespace, gathering information on local command and control for disaster response and potential disruption.
  • 2023 British Telecom Infrastructure: Heavy targeting within the Five Eyes alliance to disrupt potential mutual assistance.
  • 2022 EU Router Infrastructure: Widespread implants across router infrastructure in multiple EU member states for signals intelligence and potential disruption.

These findings underscore a sophisticated, well-resourced, and strategically aligned adversary capable of deep persistence and significant impact on global critical infrastructure.

Technical Deep Dive

▶ Watch: Quick primer on Passive DNS for threat hunting (2:20)

The technical core of Schwalbe's presentation revolves around the application of Passive DNS for threat hunting and the meticulous analysis of Salt Typhoon's domain infrastructure. Passive DNS, unlike traditional DNS, captures cache miss traffic between recursive DNS servers and authoritative name servers. This distinction is critical because it ensures the collection of fresh, authoritative data, rather than potentially stale cached records. By aggregating this information into a searchable database, investigators can ask questions that regular DNS cannot answer, providing unparalleled visibility into adversary infrastructure.

Schwalbe highlights several superpowers of Passive DNS relevant to this investigation:

  • IP-to-Domain Mapping: Given an IP address, Passive DNS can reveal all domains that have pointed to it over time. This is invaluable for identifying shared hosting infrastructure used by threat actors, as many IPs lack reverse pointer records (PTR records) or have non-matching forward/reverse entries.
  • Name Server Pivoting: Adversaries often maintain dedicated name server infrastructure. Passive DNS allows researchers to query a specific authoritative name server and identify all domains for which it is responsible. This can expose vast networks of seemingly unrelated domains controlled by the same entity.
  • Subdomain Enumeration: It provides a historical record of subdomains, enabling the discovery of malicious subdomains that might not be publicly visible or currently active.
  • Canonical Name (CNAME) Resolution: While a CNAME points one domain to another, Passive DNS can reveal the original "question" that led to a specific CNAME "answer," helping trace redirection chains.
  • Regular Expression Searches: This advanced capability allows for pattern matching across any label within an FQDN. This is particularly effective for identifying Domain Generation Algorithm (DGA) patterns, even if they have fallen out of favor, or other distinctive naming conventions used by threat actors.

Applying these techniques to Salt Typhoon's infrastructure, the DomainTools investigations team made several critical observations:

  • Infrastructure Reuse: Salt Typhoon frequently reuses its established infrastructure, which, while efficient for them, provides pivot points for defenders using Passive DNS.
  • Name Server IP Clusters: By pivoting on name server IPs, the team identified clusters of domains that, despite appearing unrelated, were managed by the same underlying infrastructure, strongly indicating common control.
  • Favorite Hosting Companies: The group exhibits preferences for certain hosting providers, although they tend to avoid hyperscalers like AWS or Azure, opting for smaller VPS providers to blend in with "script kiddie" activity and fly under the radar.
  • Distributed Operations: The research revealed a clear division of labor among the contracting companies. One entity might procure domains using false information, while another weaponizes them for phishing or other campaigns, demonstrating a well-defined playbook.
  • TLS Certificate Analysis: Salt Typhoon prefers Domain Validated (DV) TLS certificates from providers like GoDaddy or Sectigo over free options like Let's Encrypt. The rationale appears to be an attempt to project an air of legitimacy, bypassing the suspicion sometimes associated with free certificates. Crucially, the reuse of common names and private keys across multiple seemingly unrelated domains served as a strong indicator of common ownership and control.
  • Domain Registration Information: The group employs fake US personas for domain registrations, such as "Sean Francis," "Monica Burge," "Tommy Arnold," "Larry Smith," and "Gerilyn Pickkins." These generic-sounding names, often paired with ProtonMail accounts and AI-generated addresses (e.g., "Drive" and "Trails End Road"), are designed to blend in with domestic traffic and bypass geographical IP filters. The consistent use of ProtonMail for contact information and randomized alphanumeric handles within those accounts became a discernible pattern, enabling further OSINT pivoting. This strategy contrasts with straightforward private registration, indicating a calculated effort to appear legitimate while maintaining anonymity.

The detailed analysis of these patterns, made possible by the unique capabilities of Passive DNS and corroborated by the i-SOON leak, provides a granular understanding of Salt Typhoon's operational security and infrastructure management. This deep dive into their digital footprint offers actionable intelligence for defenders to detect and track their activities.

Demo / Proof of Concept

▶ Watch: Technical explanation of Passive DNS cache miss collection (3:20)

The talk primarily focused on presenting the findings of extensive research and analysis, particularly leveraging the i-SOON GitHub leak and Passive DNS techniques. There was no live technical demonstration or proof of concept shown during the presentation itself. Instead, Daniel Schwalbe referred to the published research on the DomainTools Investigations (DTI) blog, which contains detailed analysis, Indicators of Compromise (IOCs), and methodologies for how these findings were derived. The article serves as the "proof of concept" of their analytical capabilities, showing how OSINT and Passive DNS can be used to uncover complex APT infrastructure.

Defensive Implications

▶ Watch: Key capabilities and power of Passive DNS for investigations (5:00)

Understanding Salt Typhoon's operational model and TTPs, particularly as revealed through the i-SOON leak and Passive DNS analysis, provides crucial insights for defenders. Organizations, especially those in critical infrastructure sectors like telecommunications, government (including National Guard networks), and other strategic targets, must adapt their defensive strategies.

Here are key defensive implications:

  • Embrace Passive DNS for Threat Hunting: Passive DNS is highlighted as an indispensable tool for proactive threat hunting. Defenders should leverage Passive DNS platforms (whether proprietary or third-party) to:
  • Pivot on known IOCs: If an IP address is identified as malicious, use Passive DNS to find all other domains that have resolved to it.
  • Analyze Name Server Infrastructure: Query name servers associated with suspicious domains to uncover broader adversary networks.
  • Detect Domain Generation Algorithms (DGAs): Utilize regular expression searches on FQDN labels to identify DGA patterns, even if subtle.
  • Monitor for Fake Personas: Actively search WHOIS records for patterns associated with Salt Typhoon's fake personas (e.g., "Sean Francis," "Monica Burge," "Larry Smith") and the consistent use of ProtonMail for registration emails, including the distinctive randomized alphanumeric handles.
  • Scrutinize Domain Registration and Certificates:
  • WHOIS Monitoring: Implement monitoring for new domain registrations that match the identified patterns of fake US personas or generic addresses (e.g., "Drive," "Trails End Road").
  • Certificate Analysis: Pay close attention to TLS certificates. Shared common names or private keys across seemingly unrelated domains can be a strong indicator of common control by an adversary. While Salt Typhoon prefers DV certificates to appear legitimate, this can still be a unique fingerprint.
  • Strengthen Lateral Movement Detection: Given Salt Typhoon's deep persistence and ability to move laterally within networks, especially in telecom backbones, organizations must enhance internal network segmentation, implement robust endpoint detection and response (EDR) solutions, and monitor for unusual internal traffic patterns that mimic legitimate network administration.
  • Be Wary of Living Off The Land (LOTL) Binaries: Since Salt Typhoon heavily relies on LOTL binaries (e.g., PowerShell), security teams must focus on detecting abnormal usage of legitimate tools, rather than solely relying on signature-based malware detection. This requires advanced behavioral analytics and meticulous log analysis.
  • Share and Consume Threat Intelligence: The speaker emphasizes the importance of community. Organizations should consume IOCs and TTPs from reputable sources like DomainTools' research blog and threat intelligence platforms (e.g., Vertex). These IOCs, often published on GitHub, can be integrated into SIEMs, firewalls, and other security controls for automated detection.
  • Understand the Contractor Model: The shift to a contractor-enabled cyber espionage model means that adversaries may operate under the guise of legitimate companies. This necessitates a deeper investigation into the supply chain and third-party risk, as well as an understanding that "legitimate" firms might be compromised or co-opted.
  • Prepare for Dual-Use Capabilities: Recognize that deep persistence and information collection can quickly pivot to disruption. Critical infrastructure operators must not only focus on data exfiltration but also on potential sabotage or denial-of-service scenarios.

By proactively integrating these defensive measures, organizations can significantly improve their posture against sophisticated threats like Salt Typhoon and the evolving landscape of state-sponsored cyber operations.

Key Takeaways

  • Salt Typhoon is a sophisticated, state-sponsored Chinese APT group primarily focused on strategic signals intelligence and cyber battlefield preparation, with strong ties to the MSS and PLA.
  • The 2024 i-SOON GitHub leak provides unprecedented insight into the operational structure of Chinese state-sponsored cyber espionage, confirming direct links between the i-SOON firm and Salt Typhoon activities.
  • Passive DNS is an indispensable tool for threat hunting, enabling defenders to uncover hidden infrastructure, pivot on IOCs, and map adversary networks through unique capabilities like IP-to-domain resolution, name server pivoting, and regex searches.
  • Salt Typhoon employs an "industrialized" contractor model, utilizing front companies and specialized firms to execute different phases of their operations, from domain registration using fake US personas and ProtonMail accounts to infrastructure weaponization.
  • Defenders must focus on behavioral detection and OSINT, as Salt Typhoon heavily relies on living off the land binaries and attempts to blend in with legitimate traffic using generic hosting and domain validated TLS certificates.
  • The group's deep persistence in critical infrastructure, particularly telecommunications and National Guard networks, indicates dual-use capabilities for both long-term intelligence collection and potential future disruption.

About the Speaker(s)

Daniel Schwalbe is the Head of Investigations and CISO at DomainTools. With over 25 years of experience in the cybersecurity field, Daniel has a diverse background spanning state and federal government, higher education, and private industry. He came up through the ranks, having spent many years in incident response before moving into leadership roles. Daniel is a self-proclaimed "DNS nerd" and is passionate about the power of Passive DNS for threat hunting. He co-founded DomainTools Investigations approximately 18 months prior to this talk, establishing it as a research-driven practice focused on contributing valuable intelligence to the community, independent of product promotion. His expertise lies in understanding complex threat landscapes and developing innovative methods to track sophisticated adversaries.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent threat intel briefing that gets real mileage out of the i-SOON leak and Passive DNS pivoting, with some genuinely useful operational detail on Salt Typhoon's infrastructure patterns. Nothing here breaks new ground for anyone already tracking Chinese APT infrastructure, but it's honest research work rather than a vendor pitch dressed up as a talk.

Heather Calloway (CISO) — SOLID

Schwalbe delivers credible, technically grounded intelligence on Salt Typhoon's contractor model and infrastructure fingerprinting — the i-SOON leak findings are genuinely useful, and the Passive DNS methodology is well-articulated. But this is a practitioner talk that stops at the practitioner level: the defensive section reads as a checklist, and the institutional and governance dimensions of state-sponsored telco compromise go largely unaddressed.

→ Top-rated talks at BSidesSF 2026

All talks from BSidesSF 2026