TiltedTemple
Aliases: DEV-0322, Circle Typhoon
- First seen
- 2021-09-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:09:54
Targeted industries: technology-and-telecommunications government-and-public-sector healthcare-and-pharmaceutical
Targeted regions: country_code:us country_code:in
Context
One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activities have been linked to the exploitation of vulnerabilities in Zoho ManageEngine ADSelfService Plus and ServiceDesk Plus.
Exploited vulnerabilities
- CVE-2021-35211 (vulnerability)
Reports & references
- Palo Alto Unit 42 — Sockdetour (report)
- blog.fox-it.com — Ta505 Exploits Solarwinds Serv U Vulnerability Cve 2021 35211 For Initial Access (report)
- Microsoft — Microsoft Discovers Threat Actor Targeting Solarwinds Serv U Software With 0 Day Exploit (report)