Houndstooth Typhoon
Microsoft threat actor profile. Origin/Threat: China.
China-linked Houndstooth Typhoon is known for data theft and custom backdoors targeting government and critical infrastructure sectors.
Houndstooth Typhoon (also tracked as HASSIUM, DRAGNET PANDA) is a threat actor of likely Chinese origin, profiled by Microsoft. It primarily targets government entities, critical infrastructure, and telecommunications sectors. The actor employs custom tooling and backdoors for data theft, often repurposing open-source tools within its TTPs. Defenders should monitor for anomalous network traffic and suspicious PowerShell execution, especially signs of compromised credential usage.
Microsoft threat actor profile. Origin/Threat: China.
Houndstooth Typhoon primarily targets government entities, critical infrastructure, and telecommunications sectors.
Defenders should monitor for anomalous network traffic, suspicious PowerShell execution, and especially signs of compromised credential usage.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.