Passive DNS: Reverse Lookups and Pattern Hunting
Passive DNS collects cache miss traffic between recursive resolvers and authoritative name servers. Unlike regular DNS, it answers reverse lookups. Given an IP, it returns every domain that pointed there. It can pivot on name servers to list all served domains. Regular expression search across domain labels finds DGA patterns. These capabilities let analysts map adversary infrastructure that reuses hosting, certificates, or registrant information.
Salt Typhoon: Signal Intelligence and Deep Persistence
Salt Typhoon is a Chinese state-sponsored campaign linked to MSS and PLA. Its mission includes signals intelligence, long-term persistence in telecom backbone networks, and cyber battlefield preparation. It targets US, UK, Taiwan, and EU telecoms, National Guard networks, and lawful intercept systems. Operators use living-off-the-land binaries, PowerShell, and LSASS memory dumps. Domain registrations use fake US personas like Larry Smith and Sean Francis, with Proton Mail contacts.
The i-SOON Leak: Front Companies and Contractor Networks
The 2024 GitHub leak exposed i-SOON, a Chinese cybersecurity firm previously thought unlinked to state activity, as a direct operational arm of Salt Typhoon. Leaked documents including meeting minutes, invoices, and org charts revealed front companies, contractors, and hybrid firms. Three entities emerged, each with specialized expertise. The DOJ later indicted 12 contract hackers tied to i-SOON; two individuals are on the FBI most wanted list.
Domain Infrastructure: Fake Personas and Proton Mail
Passive DNS revealed Salt Typhoonβs infrastructure reuse. Name server IP clusters tied seemingly unrelated domains. TLS certificates from GoDaddy and Sectigo (not Letβs Encrypt) with shared common names proved the same operator. Domain registrations used fake personas like Sean Francis, Monica Burge, Tommy Arnold, and Larry Smith. Contact emails used Proton Mail. Hosting preferred smaller VPS providers over hyperscalers to blend in with legitimate traffic.
Takeaways: Defending Against Salt Typhoon
Salt Typhoonβs implants serve dual purposes: signals intelligence and potential infrastructure disruption. The campaign represents industrialized APT operations through contractor networks. Defenders should use passive DNS to hunt for reused infrastructure, watch for Proton Mail contacts in domain whois, and monitor for the reported fake US personas. Indicators of compromise are published on GitHub and threat intelligence platforms like VirusTotal.
Q&A
Is there evidence of Salt Typhoon targeting carrier location determination functions? Not directly, but they likely target mobile operator systems for locating individuals. βΆ 33:58
Are there kinetic or real world effects from National Guard network compromises? The main goal is understanding communication and response plans, which could be used to target critical infrastructure downstream. βΆ 35:00
What trends in hosting infrastructure do they use? They prefer smaller VPS providers, not AWS or Azure, to avoid attention. βΆ 36:17
Where can organizations get IOCs and TTPs? Published on GitHub and threat intel platforms like VirusTotal. βΆ 38:15
Do they use privacy protection services for domains? No, they prefer fake personas to hide in plain sight. βΆ 39:20
Notable Quotes
direct operation ties between ISON and um Salt Typhoon Daniel Schwalbe Β· βΆ 18:41
Sean Francis, Monica Burge, Tommy Arnold, and Larry Smith. Can you get more generic than that? Daniel Schwalbe Β· βΆ 29:20
they really love proton mail. You know make of that as you will. Daniel Schwalbe Β· βΆ 30:00
the ministry of state security, Chinese ministry of state security and the PLA strategic support force are sponsoring the salt typhoon campaign Daniel Schwalbe Β· βΆ 11:12
Key Takeaways
- Passive DNS is the most effective tool for mapping adversary infrastructure reuse.
- Salt Typhoon uses fake US personas and Proton Mail for domain registration.
- The i-SOON leak revealed a contractor ecosystem enabling turnkey APT operations.
About the Speaker(s)
Daniel Schwalbe is a proven information security and privacy leader with 25 years of operational and strategic information security practice in startup, higher education, government, and large enterprise settings. He is an active contributor to the information security and privacy community.