Unknown · assessed origin China
TiltedTemple
DEV-0322Circle Typhoon
misp-galaxyrefreshed 2026-09-15
sigil
Analyst brief
One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activities have been linked to the exploitation of vulnerabilities in Zoho ManageEngine ADSelfService Plus and ServiceDesk Plus.
Early access
Track TiltedTemple on the wire.
Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.
bot-protected