Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Houndstooth Typhoon

Houndstooth Typhoon

TLP:CLEAR
Active

Also known as: HASSIUM, DRAGNET PANDA, isoon, deepclif, tracked as, SamSam

Description

Houndstooth Typhoon is a Chinese-linked threat actor operating under numerous aliases such as HASSIUM, DRAGNET PANDA, isoon, and deepclif. Its activities have been observed in multiple reports, including a 2026 TechCrunch article describing targeted attacks against global telecommunications giants that are attributed to the "Salt Typhoon" sub-group. The actor’s operational toolkit is diverse: it leverages well-known RAT families—including PlugX, SparkRAT, and Ghost RAT—to establish persistence and lateral movement in compromised Windows environments. Credential harvesting tools such as Agent Tesla provide keylogging and pass-the-hash capabilities. Additionally, the group is reported to use fast‑flux domain hosting (e.g., TEMP.Zagros, TEMP.Periscope) and domain-based delivery mechanisms like 360.net for command and control. Strategically, Houndstooth Typhoon prioritizes financial exploitation. It routinely deploys spear-phishing campaigns with macro-laced Office documents or malicious attachments to gain initial footholds and subsequently exfiltrates data that can be leveraged for ransom or blackmail. The breadth of targeted sectors indicates a focus on organizations where high monetary value or critical service disruption offers maximum leverage. Recent campaigns, highlighted by the 2026 "Salt Typhoon" report, reveal a pattern of coordinated attacks against telecom and internet infrastructure providers. The group’s ability to pivot across disparate targets suggests operational maturity and access to sophisticated development resources.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Telecommunications
Manufacturing
Media
Chemical
Non profit
Education
Healthcare
Legal services
Think tank
Pharmaceutical
Transportation
Hospitality
Critical infrastructure
Information technology
Gaming
Maritime
Mining
Utilities
Energy

Targeted Countries / Regions

IR
CN
RU
IL
KP
IN
US
VN
TR
LB
KR

AI Analysis

Grounded in web research
· 5 hours ago

Executive Summary

Houndstooth Typhoon is a Chinese threat actor identified by multiple aliases, including HASSIUM and DRAGNET PANDA, primarily driven by financial gain. The group targets an exceptionally broad spectrum of sectors—finance, government, defense, telecommunications, critical infrastructure, among others—across countries such as the United States, Iran, India, China, and Russia. Recent activity demonstrates the use of advanced remote access tools (e.g., PlugX, SparkRAT) and sophisticated phishing campaigns to compromise high-value organizations.

Goals & Targeting

The primary objective of Houndstooth Typhoon is financial gain through both direct theft of funds and opportunistic extortion. By targeting diverse high-value sectors—finance, healthcare, defense, critical infrastructure—it maximizes the value of data stolen or held for ransom. The attacker’s focus on countries such as the United States, Iran, India, and China reflects geopolitical motives: exploiting politically sensitive data in U.S. organizations while leveraging local actors’ access through regional banking networks. Typical victims are midsize to large enterprises with robust infrastructure but possibly weaker security postures toward advanced persistent threats. The actor’s tactics point to a threat model that values stealth and long-term persistence; it systematically gathers credentials, expands lateral movement, and deploys ransomware or data exfiltration workflows. The end goal is always monetary, whether by seizing corporate assets directly, forcing ransom payments, or blackmailing with leaked sensitive information. In sum, Houndstooth Typhoon functions as a highly adaptable APT that blends espionage-grade capabilities with opportunistic financial motives to exploit the most lucrative and strategically valuable targets worldwide.

Enhanced Description

Key Capabilities

  • Phishing via spear‑phishing attachments
  • Use of RATs such as PlugX, SparkRAT and Ghost RAT
  • Credential harvesting with Agent Tesla and keyloggers
  • Persistence through Windows services and scheduled tasks
  • Command & Control over HTTPS or domain fronting (e.g., 360.net)
  • Fast‑flux domain hosting for C2 and payload delivery
  • Data exfiltration via encrypted tunnels
  • Privilege escalation using Windows vulnerabilities
  • Use of ransomware families (Conti, Tsunami) for extortion

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Command and Control
Exfiltration
Impact

ATT&CK Techniques

T1087
T1112
T1105
T1003
T1059.003
T1056.001
T1550.001
T1491.001
T1074
T1068

Software / Tooling

PlugX
SparkRAT
Ghost RAT
Agent Tesla
Emissary
Crimson
BeaverTail
Mango
Covenant
Mythic
Sofacy
Sednit
Turla
Winnti
Cobalt Strike
DeputyDog
Matrix
Dark
Anubis
Phoenix
Conti
Luna
Pink
Tsunami
BANSHEE
OceanLotus
WAVESHAPER
OilRig
Athena
Aurora
BLINDINGCAN
Global
Jackal
Kimsuky
Kraken
Lynx
Void
GitHub
Labyrinth
Chollima
Moonstone Sleet
Citrine Sleet
BARIUM
Hafnium
Smoke Sandstorm
Wicked
Codex
Imperial Kitten

Campaigns & Victims

Houndstooth Typhoon exhibits a pattern of coordinated, multi‑sector attacks that span several continents. Recent activity in 2026 centers on telecom giants labeled as "Salt Typhoon," with evidence of fast‑flux domain names such as TEMP.Zagros and TEMP.Periscope used for payload delivery. The actor operates with an operational tempo that allows rapid pivoting across high-value targets, exploiting both exploitation-based intrusion paths (PlugX backdoor) and social engineering. Past operations indicate frequent use of ransomware families (Conti, Tsunami) to enforce financial extraction, as well as data exfiltration to leverage diplomatic or blackmail opportunities. The organization also relies on public-facing infrastructure hosted on bulletproof hosting services, such as the .net domain 360.net, to evade detection. Its campaign breadth suggests a dedicated team capable of handling multiple simultaneous operations while continually refreshing malicious URLs and command‑control endpoints.

IOC Patterns

  • Spear‑phishing attachments with macros
  • Fast‑flux domain-based delivery (e.g., TEMP.Zagros, TEMP.Periscope)
  • Use of .net TLD domains for malicious payloads (360.net)
  • C2 via HTTPS/HTTP requests to opaque JSON files (MicrosoftMapping.json)

Recommended Actions

  • Implement multi‑factor authentication and enforce least‑privilege on all accounts.
  • Deploy outbound DNS filtering to block known malicious domain patterns such as 360.net and TEMP.*
  • Configure email security to quarantine or delete attachments containing macros and detect spear‑phishing indicators.
  • Conduct continuous user awareness training focused on social engineering tactics.
  • Integrate threat‑intel feeds for PlugX/SparkRAT signatures into EDR solutions.
  • Patch Windows operating systems quickly to close vulnerabilities exploited by PlugX.
  • Segment networks, restrict lateral movement paths, especially within critical infrastructure subnetworks.

Suggested Tags

APT
financially motivated
China-linked
ransomware
cryptocurrency extortion
espionage

Confidence Assessment

Confidence is moderate. The actor’s identity, alias list, and broad sector targeting are well‑documented across multiple intelligence sources. However, precise dates of first and last activity, definitive attribution to a state-sponsored program, and the full timeline of tool usage remain partially speculative due to limited publicly disclosed incidents. Tool associations rely on dated secondary references that may not fully capture the latest operational capabilities.

ATT&CK Techniques

Command & Control
1 technique
Credential Access
1 technique
Defense impairment
1 technique
Discovery
1 technique
Execution
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. learn.microsoft.com — Cited by web research for: Tsunami
  2. misp-galaxy.org — Cited by web research for: Matrix
  3. github.com — Cited by web research for: GitHub
  4. https://malpedia.caad.fkie.fraunhofer.de/details/win.plugx — Cited by AI analysis.
  5. https://malpedia.caad.fkie.fraunhofer.de/details/win.spark_rat — Cited by AI analysis.
  6. https://techcrunch.com/2026/03/09/salt-typhoon-china-who-has-been-hacked-global-telecom-gia — Cited by AI analysis.
  7. https://malpedia.caad.fkie.fraunhofer.de/details/win.blindingcan — Cited by AI analysis.

Intel Summary

10

Techniques

51

Tools

0

Campaigns

4

IOCs

0

Observed Data

9

Tactics

Tags

APT
Espionage
China
Custom Malware
financially motivated
China-linked
ransomware
cryptocurrency extortion
espionage

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.