TiltedTemple

Aliases: DEV-0322, Circle Typhoon

First seen
2021-09-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:09:54

Targeted industries: technology-and-telecommunications government-and-public-sector healthcare-and-pharmaceutical

Targeted regions: country_code:us country_code:in

Context

One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activities have been linked to the exploitation of vulnerabilities in Zoho ManageEngine ADSelfService Plus and ServiceDesk Plus.

Exploited vulnerabilities

  • CVE-2021-35211 (vulnerability)

Reports & references

  • Palo Alto Unit 42 — Sockdetour (report)
  • blog.fox-it.com — Ta505 Exploits Solarwinds Serv U Vulnerability Cve 2021 35211 For Initial Access (report)
  • Microsoft — Microsoft Discovers Threat Actor Targeting Solarwinds Serv U Software With 0 Day Exploit (report)

External references