Salt Typhoon is a China-linked cyber espionage threat actor focused primarily on telecommunications and network infrastructure, with operations associated with long-term strategic intelligence collection. The group is widely tracked under multiple aliases including GhostEmperor, Earth Estries, FamousSparrow, Operator Panda, RedMike, UNC2286, and UNC5807. Public reporting also places the actor within the broader ecosystem of Chinese state-aligned intrusion activity and private-sector enabling firms that support espionage operations on behalf of the People’s Republic of China. Salt Typhoon is best known for compromising telecommunications providers and gaining access to core network environments. Reported operations included persistent access inside major U.S. telecom providers and access to lawful-intercept systems, demonstrating an ability to operate at the carrier level rather than only against enterprise edge assets. The group’s targeting aligns with strategic collection priorities such as communications intelligence, subscriber and network metadata access, and durable positioning in critical communications infrastructure. Telecommunications entities are the clearest high-confidence target set, though the actor is also discussed alongside broader Chinese targeting of government and critical infrastructure environments. Tradecraft attributed to Salt Typhoon reflects a mature post-compromise methodology centered on stealth, persistence, and living-off-the-land behavior. Reporting associates the actor with overlap in discovery, credential access, defense evasion, and tool acquisition techniques commonly seen across several Chinese espionage groups. Analysts have highlighted the group’s use of modular and reusable tooling rather than relying exclusively on bespoke malware. Salt Typhoon activity has also been linked to network-device and telecom-focused operations, including suspicious tunnel configuration behavior and protocol tunneling patterns on Cisco IOS-XE devices. Publicly discussed detections tied to the group also reference command execution patterns on network infrastructure consistent with exploitation or post-exploitation activity. The actor is frequently described as difficult to profile comprehensively because public reporting on its full technique set remains more limited than for some other Chinese intrusion groups. Even so, available evidence consistently places Salt Typhoon among advanced PRC-linked espionage actors that prioritize covert access, operational security, and strategic collection over disruptive effects. The group is often compared with or analyzed alongside other Chinese state-sponsored clusters such as Volt Typhoon, Flax Typhoon, APT41, Mustang Panda, and Stone Panda because of overlapping tactics and shared patterns in enterprise and infrastructure intrusion tradecraft. Salt Typhoon should be understood as a high-capability Chinese espionage actor with a demonstrated interest in telecom backbone access and other positions that enable broad intelligence collection. Its operations illustrate the strategic value Beijing places on communications infrastructure compromise, persistence in trusted network environments, and the use of blended operational ecosystems involving both state direction and commercially enabled support.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
66 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
33 malware families attributed to this actor across reporting.
28 additional families tracked in Mallory.
24 CVEs this actor has used in observed campaigns. 24 of them exploited in the wild.
The Australian Signals Directorate (ASD) recently issued a high-severity alert about an ongoing cyber attack campaign exploiting a critical vulnerability in Cisco IOS XE devices, tracked as CVE-2023-20198. This vulnerability has a perfect CVSS score of 10.0, reflecting its extreme risk, and has been actively exploited since 2023.
The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain... ProxyNotShell (CVE-2022-41040, CVE-2022-41082) is a related exploit chain disclosed in 2022. Both allow unauthenticated attackers to execute code on unpatched Exchange servers.
In 2025, it was reported that Russian government-sponsored ransomware gangs Static Tundra and Salt Typhoon exploited the CVE-2018–0171 vulnerability in unpatched Cisco equipment. The CVE-2018–0171 vulnerability in Cisco IOS and IOS XE allows a remote threat actor to execute arbitrary commands without authentication, and it was disclosed that the vulnerability was used to gain initial access.
Both groups were also early exploiters of the ProxyLogon vulnerability (CVE-2021-26855) and have used some of the same publicly available tools.
Salt Typhoon has exploited vulnerabilities in Cisco edge devices (notably CVE-2023-20198 and CVE-2023-20273) to gain unauthorized access to telecom networks.
19 more CVEs tied to this actor tracked in Mallory.
160 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of detectable active network intrusion activity, contrasted with undetectable passive HNDL collection.
Mentioned only as a comparison point for overlapping TTPs, not as a primary actor in the reported campaign.
Mentioned as another state-sponsored group that may use the same weaknesses and techniques against networking devices.
Mentioned only as a comparison point for overlapping techniques with the primary Russian actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.