Also known as: HASSIUM, DRAGNET PANDA, isoon, deepclif, tracked as, SamSam
Houndstooth Typhoon is a Chinese-linked threat actor operating under numerous aliases such as HASSIUM, DRAGNET PANDA, isoon, and deepclif. Its activities have been observed in multiple reports, including a 2026 TechCrunch article describing targeted attacks against global telecommunications giants that are attributed to the "Salt Typhoon" sub-group. The actor’s operational toolkit is diverse: it leverages well-known RAT families—including PlugX, SparkRAT, and Ghost RAT—to establish persistence and lateral movement in compromised Windows environments. Credential harvesting tools such as Agent Tesla provide keylogging and pass-the-hash capabilities. Additionally, the group is reported to use fast‑flux domain hosting (e.g., TEMP.Zagros, TEMP.Periscope) and domain-based delivery mechanisms like 360.net for command and control. Strategically, Houndstooth Typhoon prioritizes financial exploitation. It routinely deploys spear-phishing campaigns with macro-laced Office documents or malicious attachments to gain initial footholds and subsequently exfiltrates data that can be leveraged for ransom or blackmail. The breadth of targeted sectors indicates a focus on organizations where high monetary value or critical service disruption offers maximum leverage. Recent campaigns, highlighted by the 2026 "Salt Typhoon" report, reveal a pattern of coordinated attacks against telecom and internet infrastructure providers. The group’s ability to pivot across disparate targets suggests operational maturity and access to sophisticated development resources.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Houndstooth Typhoon is a Chinese threat actor identified by multiple aliases, including HASSIUM and DRAGNET PANDA, primarily driven by financial gain. The group targets an exceptionally broad spectrum of sectors—finance, government, defense, telecommunications, critical infrastructure, among others—across countries such as the United States, Iran, India, China, and Russia. Recent activity demonstrates the use of advanced remote access tools (e.g., PlugX, SparkRAT) and sophisticated phishing campaigns to compromise high-value organizations.
Goals & Targeting
The primary objective of Houndstooth Typhoon is financial gain through both direct theft of funds and opportunistic extortion. By targeting diverse high-value sectors—finance, healthcare, defense, critical infrastructure—it maximizes the value of data stolen or held for ransom. The attacker’s focus on countries such as the United States, Iran, India, and China reflects geopolitical motives: exploiting politically sensitive data in U.S. organizations while leveraging local actors’ access through regional banking networks. Typical victims are midsize to large enterprises with robust infrastructure but possibly weaker security postures toward advanced persistent threats. The actor’s tactics point to a threat model that values stealth and long-term persistence; it systematically gathers credentials, expands lateral movement, and deploys ransomware or data exfiltration workflows. The end goal is always monetary, whether by seizing corporate assets directly, forcing ransom payments, or blackmailing with leaked sensitive information. In sum, Houndstooth Typhoon functions as a highly adaptable APT that blends espionage-grade capabilities with opportunistic financial motives to exploit the most lucrative and strategically valuable targets worldwide.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Houndstooth Typhoon exhibits a pattern of coordinated, multi‑sector attacks that span several continents. Recent activity in 2026 centers on telecom giants labeled as "Salt Typhoon," with evidence of fast‑flux domain names such as TEMP.Zagros and TEMP.Periscope used for payload delivery. The actor operates with an operational tempo that allows rapid pivoting across high-value targets, exploiting both exploitation-based intrusion paths (PlugX backdoor) and social engineering. Past operations indicate frequent use of ransomware families (Conti, Tsunami) to enforce financial extraction, as well as data exfiltration to leverage diplomatic or blackmail opportunities. The organization also relies on public-facing infrastructure hosted on bulletproof hosting services, such as the .net domain 360.net, to evade detection. Its campaign breadth suggests a dedicated team capable of handling multiple simultaneous operations while continually refreshing malicious URLs and command‑control endpoints.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is moderate. The actor’s identity, alias list, and broad sector targeting are well‑documented across multiple intelligence sources. However, precise dates of first and last activity, definitive attribution to a state-sponsored program, and the full timeline of tool usage remain partially speculative due to limited publicly disclosed incidents. Tool associations rely on dated secondary references that may not fully capture the latest operational capabilities.
No campaigns linked yet.
No observed data linked yet.
10
Techniques
51
Tools
0
Campaigns
4
IOCs
0
Observed Data
9
Tactics