ATT&CKSoftwareJumbledPath

JumbledPath

S1206

Malware.View on attack.mitre.org

About this malware

JumbledPath is a custom-built utility written in GO that has been used by Salt Typhoon since at least 2024 for packet capture on remote Cisco devices. JumbledPath is compiled as an ELF binary using x86-64 architecture which makes it potentially useable across Linux operating systems and network devices from multiple vendors.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1040
Network Sniffing

JumbledPath has the ability to perform packet capture on remote devices via actor-defined jump-hosts.

T1104
Multi-Stage Channels

JumbledPath can communicate over a unique series of connections to send and retrieve data from exploited devices.

T1560
Archive Collected Data

JumbledPath can compress and encrypt exfiltrated packet captures from targeted devices.

T1665
Hide Infrastructure

JumbledPath can use a chain of jump hosts to communicate with compromised devices to obscure actor infrastructure.

T1685
Disable or Modify Tools

JumbledPath can impair logging on all devices used along its connection path to compromised hosts.

T1685.006
Clear Linux or Mac System Logs

JumbledPath can clear logs on all devices used along its connection path to compromised network infrastructure.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cisco Salt Typhoon FEB 2025 Open source
    Cisco Talos. (2025, February 20). Weathering the storm: In the midst of a Typhoon. Retrieved February 24, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.