TechDogs-"Global Cyber Threats Grow: Salt Typhoon, Nimbus Manticore & Fake GitHub Pages"

Cyber Security

Global Cyber Threats Grow: Salt Typhoon, Nimbus Manticore & Fake GitHub Pages

By Manali Kekade

Updated on Tue, Sep 23, 2025

Overall Rating
A year after Salt Typhoon, a Chinese-linked hacking group, shook global telecom giants, its influence remains. The tactics used by the cybercriminal group are now surfacing in the playbooks of other attackers.

Salt Typhoon had broken into leading telecom networks, including AT&T and Verizon, before being forced out. However, its methods left a mark. At the Google Cloud Cyber Defense Summit, AT&T’s Chief Information Security Officer, Rich Baich, explained how the group changed the game.

Baich pointed to three tactics that stood out. First, the group targeted platforms without endpoint detection and response (EDR), avoiding the systems that are often well-protected.

Second, they searched for areas of networks where no logs existed, making it easier to move undetected. Third, they relied on “living off the land” attacks, using the company’s own administrative tools instead of malware, blending in with normal activity.

“We’re seeing adversaries really change the way they’re doing things, very similar to what Salt Typhoon did,” said Rich Baich, during the Google Cloud Cyber Defense Summit.

TechDogs-"An Image Showing System Hacked Sign"
“What we need to think about is this: Do we need to have endpoint protection elsewhere, in different platforms?” Baich stated, adding that companies must lock down administrative tools and understand how their own systems can be misused.

Former NSA cybersecurity director, Rob Joyce, echoed the concern, saying, “Defenses for the most-used technology in society today — from mobile phones to web browsers — have gotten very good, Joyce said at the same conference. Vulnerability management, patch management, threat intelligence — all have bolstered defenses.”

“At the same time, we’ve evolved the attackers through that activity. I think by calling out some of the bad behavior, by highlighting the things that have worked or not worked, we’ve pushed people into new exploit methodology,” Joyce added.

This highlights that as hackers adapt, companies must look past traditional defenses and secure the blind spots they’ve long ignored.

Well, those blind spots have gone beyond telecom networks to MacOS users.

Mac users are the latest target in a crafty malware campaign that hijacks the trustworthiness of GitHub.

Researchers from LastPass’s Threat Intelligence, Mitigation, and Escalation (TIME) team revealed on September 18 that attackers are creating fake GitHub repositories disguised as macOS versions of popular apps.

The setup is convincing: repositories are stuffed with Mac-related keywords, giving them a better chance of appearing high in search results. Once users land on the page, they’re instructed to run a simple line of code in their Mac terminal. However, that code secretly downloads Atomic infostealer (AMOS), a malware designed to steal sensitive data.

One phony listing even claimed to be “LastPass Premium on MacBook.” According to researchers Alex Cox, Mike Kosak, and Stephanie Schneider, the campaign utilizes multiple GitHub usernames, all of which push near-identical, keyword-heavy repositories.

The bigger picture is that hackers are leveraging SEO-based campaigns on trusted platforms to lure victims into lowering their guard.

The campaign has targeted companies across both the technology and financial sectors, with LastPass itself among the targets. It is part of a broader trend in which attackers exploit trusted platforms, such as GitHub, to spread malware. Similar incidents include the Shai-Hulud worm, the compromise of NPM developer Qix, and the Salesloft breach.

The rise of this deceptive malware campaigns comes in close succession to another escalation from Iran-linked hackers.

Iran-based hacking group, Nimbus Manticore, also tracked as UNC1549 or Smoke Sandstorm, is intensifying its operations in Europe, targeting critical industries with new and enhanced malware.

Researchers at Check Point Software reported that the group has recently gone after defense, telecom, and aviation companies in Denmark, Portugal, and Sweden.

The main drivers of the campaign are two tools, MiniJunk, a backdoor that provides long-term access to compromised systems, and MiniBrowse, a tool for stealing browser credentials.

MiniJunk, an evolution of earlier malware, can now move files, run programs, and connect with multiple hidden servers. To stay undetected, it uses layers of obfuscation and even fake digital certificates.

The attacks often begin with fake job emails pretending to come from companies like Airbus, Boeing, or Rheinmetall. When victims visit the fake sites and download a file, hidden malware is installed in the background, disguised as legitimate software.

Check Point described the new campaign as a “significant increase in the actor’s abilities,” pointing to sophisticated code techniques to slow down defenders and researchers. Active since at least 2022, Nimbus Manticore’s latest wave of attacks signals a widening focus on Europe’s critical infrastructure.

Can Europe’s critical industries handle the growing wave of state-backed cyber-attacks? What can GitHub do to avoid attackers exploiting its reputation and trust?

Let us know your thoughts in the comments section below!

First published on Tue, Sep 23, 2025

Liked what you read? That’s only the tip of the tech iceberg!

Explore our vast collection of tech articles including introductory guides, product reviews, trends and more, stay up to date with the latest news, relish thought-provoking interviews and the hottest AI blogs, and tickle your funny bone with hilarious tech memes!

Plus, get access to branded insights from industry-leading global brands through informative white papers, engaging case studies, in-depth reports, enlightening videos and exciting events and webinars.

Dive into TechDogs' treasure trove today and Know Your World of technology like never before!

Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.

Loading comments...

  • Dark
  • Light