JumbledPath is a bespoke Go-based ELF utility associated with the China-linked espionage group Salt Typhoon. It is designed for remote packet capture on compromised network infrastructure, including Cisco devices, and can operate through actor-defined jump-host chains to reach targeted systems indirectly. The tool has been used in long-term intrusions against telecommunications environments, where it supported covert monitoring of network traffic and collection of potentially sensitive communications and authentication data.
In addition to packet capture, JumbledPath can compress and encrypt captured data prior to exfiltration, indicating a collection-and-staging role within espionage operations. It also includes defense-evasion functionality: it can clear logs and disable or impair logging on devices along its connection path, reducing forensic visibility and complicating incident response. Reported use of JumbledPath aligns with Salt Typhoon tradecraft focused on living-off-the-land access to network devices, persistence in telecom infrastructure, and surveillance-oriented collection rather than disruptive effects.
JumbledPath is best characterized as a specialized network-focused collection utility used in state-linked cyber espionage, particularly against telecommunications providers and network infrastructure environments running Linux-based or ELF-supporting network-device components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
JumbledPath. Ключевой кастомный инструмент - утилита для удалённого перехвата пакетов через цепочку скомпрометированных устройств. По данным Cisco Talos, JumbledPath написан на Go и скомпилирован как ELF-бинарь.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
APT5 'used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring'; BOLDMOVE 'can disable the Fortinet daemons moglogd and syslogd to evade detection and logging'; JumbledPath 'can impair logging on all devices used along its connection path'; Cutting Edge 'disabled logging'.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
Multiple malware and groups are described as zipping/archiving/packing collected data prior to exfiltration (e.g., "used ZIP to compress data gathered on a compromised host", "packs collected data into a password protected archive", "archived victim's data prior to exfiltration").
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom tool used for remote packet capture through a chain of compromised network devices, obscuring the true interception source.
A custom malicious tool used to stealthily monitor network traffic on compromised telecom networks, likely to capture sensitive data.
JumbledPath is a custom Go-based ELF binary used by the Salt Typhoon threat actor to perform packet capture on remote Cisco devices via a jump-host. It can also clear and disable logs to evade detection and hinder forensic analysis.
Tool capable of remote packet capture via actor-defined jump hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.