Several Chinese state-aligned advanced persistent threat (APT) groups have recently demonstrated both an expansion in targeting priorities and a noticeable evolution in their malware ecosystems. Recent investigations show these actors adapting their operations to geopolitical developments while continuing to refine long-term persistence strategies, modular malware delivery, and stealth-focused intrusion techniques.

Salt Typhoon Shifts Focus Toward Strategic Energy Infrastructure

During the period between December 2025 and February 2026, researchers identified a cyber-espionage operation attributed to Salt Typhoon, a Chinese-linked threat actor also tracked under the names Earth Estries, FamousSparrow, GhostEmperor, and UNC2286. The campaign targeted an Azerbaijani oil and gas organization, representing a meaningful shift from the group’s traditionally observed focus on telecommunications providers, government entities, and technology sectors across regions including North America, Asia, Africa, and the Middle East.

Security analysts believe the operation was closely tied to changing geopolitical and energy conditions. With the termination of Russia’s gas transit agreement involving Ukraine, combined with ongoing instability affecting shipping activity through the Strait of Hormuz, Azerbaijan has become increasingly important as an alternative energy supplier to Europe. Researchers assessed that this elevated strategic importance likely made Azerbaijani energy infrastructure a high-value intelligence target for Chinese cyber-espionage operations. Bitdefender, which investigated the activity, linked the campaign to Salt Typhoon with moderate-to-high confidence.

The attack sequence began with exploitation of Microsoft Exchange vulnerabilities associated with the ProxyNotShell exploit chain. After successfully compromising externally accessible systems, the attackers installed web shells to establish reliable remote access and maintain persistence within the victim environment.

Following the initial breach, the operators deployed the Deed RAT malware using DLL sideloading techniques. To reduce suspicion and evade detection, the malicious components were stored inside directory paths crafted to resemble legitimate installations of LogMeIn Hamachi software. Persistence mechanisms were similarly disguised through the creation of startup services designed to appear legitimate to administrators and security tools.

Once stable access had been established, the attackers expanded deeper into the network environment. Remote Desktop Protocol (RDP) sessions were used to pivot to additional servers, while Impacket-based tooling enabled credential abuse and facilitated compromise of further internal systems.

Investigators also observed that the operation continued well after initial remediation efforts. Approximately one month after the malware was removed, the threat actors regained access to the originally compromised infrastructure and introduced an additional backdoor known as TernDoor, previously associated with Salt Typhoon by Cisco Talos researchers. Later intrusion attempts observed in February involved efforts to redeploy Deed RAT using nearly identical execution workflows and infrastructure patterns.

Researchers concluded that the campaign was not an isolated intrusion or a short-lived compromise. Instead, it reflected a sustained intelligence-gathering operation in which the attackers continuously attempted to re-establish persistence, introduce replacement malware, and broaden their access across the target network despite defensive countermeasures.

Twill Typhoon Deploys Updated Modular Remote Access Malware

Separate research conducted by Darktrace revealed ongoing activity associated with Twill Typhoon, another China-linked threat actor also known as Bronze President, Camaro Dragon, Earth Preta, Mustang Panda, and TA416. Between September 2025 and at least April 2026, the group targeted organizations throughout the Asia-Pacific region and Japan while deploying an updated malware ecosystem centered around a newly identified modular .NET-based remote access platform.

During the campaign, compromised systems repeatedly communicated with attacker-controlled domains crafted to imitate legitimate online infrastructure, including services associated with Yahoo and Apple. These spoofed domains delivered legitimate executable files together with matching configuration data and malicious DLL payloads. This delivery method is consistent with DLL sideloading techniques frequently observed in operations attributed to Chinese state-sponsored groups.

The final stage of the infection chain resulted in deployment of a newly identified remote access framework referred to as FDMTP. The malware was executed through sideloading mechanisms that abused trusted Windows application workflows in order to reduce the likelihood of detection.

Analysis of the framework revealed a highly modular architecture designed to support a broad set of post-compromise operations. The malware included capabilities for system reconnaissance, command execution, scheduled task manipulation, registry-based persistence, process management, and remote retrieval of additional files or payloads.

Researchers further determined that the framework abused legitimate Visual Studio hosting mechanisms together with Microsoft’s ClickOnce deployment technology. By leveraging trusted Windows components, the malware blended malicious activity with legitimate software behavior, complicating detection and forensic analysis.

Darktrace observed that during the earlier stages of the campaign in late 2025, infected hosts repeatedly downloaded identical malicious DLL files from external infrastructure. However, by April 2026, the operational pattern had evolved. In one observed case involving a financial-sector organization, a compromised system first downloaded a legitimate executable before repeatedly retrieving updated configuration files and replacement malware modules. This behavior strongly suggested that the operators were actively maintaining and modifying the deployed malware environment over time.

According to researchers, the distributed plugin-oriented structure of the FDMTP framework provides significant operational flexibility. Individual malware modules can be independently updated, replaced, or reloaded without disrupting the broader intrusion platform. This design improves resilience, supports long-term persistence, and reflects the increasingly sophisticated engineering practices commonly associated with modern Chinese cyber-espionage operations.