Salt Typhoon is a China-linked state-affiliated espionage threat actor focused on long-term compromise of telecommunications and network infrastructure. The group has been active since at least 2019 and is widely associated with sustained cyber espionage operations against major telecom providers, particularly in the United States, with reporting also tying its activity to broader targeting of global telecommunications networks and some government-related entities. Common aliases associated with this actor include GhostEmperor, Earth Estries, FamousSparrow, RedMike, Operator Panda, UNC2286, and UNC5807. Some reporting also links or associates the cluster with KELP. Public naming is inconsistent across vendors, but Salt Typhoon is the most widely recognized name in current industry and government usage. Salt Typhoon is notable for targeting core telecom environments rather than relying primarily on conventional endpoint malware. Its operations have included compromise of routers, switches, and adjacent server infrastructure; abuse of valid accounts; use of network-device command-line interfaces; collection of device configurations; creation of additional accounts; modification of access controls; and use of built-in device capabilities for persistence and surveillance. In at least one confirmed case, the actor exploited CVE-2018-0171 in Cisco Smart Install, but valid-account abuse appears to be the primary access mechanism in most reported intrusions. The group’s tradecraft emphasizes stealth, persistence, and living-off-the-land techniques. Reported behaviors include activation of Cisco Guest Shell, establishment of persistent remote access on nonstandard management channels, use of compromised network devices as pivot points, traffic mirroring for collection, and tunneling through standard network protocols to move data and maintain command and control. On supporting server infrastructure, Salt Typhoon has also been linked to tooling such as GhostSpider, Demodex, SnappyBee, HemiGate, and Cobalt Strike, as well as DLL sideloading through legitimate software. Operational objectives are consistent with strategic state espionage: interception of communications, mapping of internal telecom networks, theft of sensitive configuration and access data, compromise of lawful-intercept environments, and maintenance of prepositioned access that could support future intelligence collection or disruptive operations. Public reporting has described intrusions affecting major U.S. carriers including AT&T, Verizon, T-Mobile, Lumen Technologies, and Charter Communications, with some compromises reportedly persisting for years. Behaviorally, Salt Typhoon overlaps with other Chinese intrusion sets such as Volt Typhoon in its use of legitimate administration mechanisms, low-malware operations, and emphasis on persistence in critical infrastructure. However, Salt Typhoon is distinguished by its concentration on telecommunications espionage and surveillance. Defensively relevant ATT&CK-aligned behaviors include Valid Accounts, Network Device CLI, Web Shell, Data from Configuration Repository, Traffic Duplication, Protocol Tunneling, and use of network infrastructure as operational pivot points.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
67 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
34 malware families attributed to this actor across reporting.
29 additional families tracked in Mallory.
24 CVEs this actor has used in observed campaigns. 24 of them exploited in the wild.
The Australian Signals Directorate (ASD) recently issued a high-severity alert about an ongoing cyber attack campaign exploiting a critical vulnerability in Cisco IOS XE devices, tracked as CVE-2023-20198. This vulnerability has a perfect CVSS score of 10.0, reflecting its extreme risk, and has been actively exploited since 2023.
CVE-2018-0171 - активно эксплуатируемая уязвимость (CISA KEV) в функции Smart Install Cisco IOS и IOS XE. CVSS 3.1: 9.8 (CRITICAL)... Атакующий отправляет crafted Smart Install-пакет на TCP-порт 4786 - результат: перезагрузка (DoS) или выполнение произвольного кода.
The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain... ProxyNotShell (CVE-2022-41040, CVE-2022-41082) is a related exploit chain disclosed in 2022. Both allow unauthenticated attackers to execute code on unpatched Exchange servers.
Both groups were also early exploiters of the ProxyLogon vulnerability (CVE-2021-26855) and have used some of the same publicly available tools.
Salt Typhoon has exploited vulnerabilities in Cisco edge devices (notably CVE-2023-20198 and CVE-2023-20273) to gain unauthorized access to telecom networks.
19 more CVEs tied to this actor tracked in Mallory.
160 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the espionage campaign that prompted proposed cybersecurity protections for UK telecoms networks.
Mentioned as an example of a state-sponsored group involved in campaigns targeting vulnerable network edge devices and telecommunications providers.
China-linked APT focused on long-term covert access in telecommunications and critical infrastructure.
Referenced as an example of a sophisticated state-sponsored threat actor using living-off-the-land style tradecraft to persist in compromised networks and access sensitive government data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.