Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareUsed by 1 actor

Salt Typhoon

Salt Typhoon is a Chinese state-backed advanced persistent threat group assessed to be operated by the PRC Ministry of State Security (MSS). It is also referred to in the provided content as GhostEmperor, FamousSparrow, Earth Estries, and UNC2286. The group has conducted cyber-espionage operations against the United States and more than 80 other countries, with a particular focus on telecommunications infrastructure, ISPs, government entities, hotels, and private companies. Reported activity includes compromise of U.S. telecom infrastructure, access to metadata on more than one million U.S. mobile phone users, and access to systems used for court-authorized wiretapping.

The content states that Salt Typhoon relies on exploitation of vulnerabilities, including zero-days and remote code execution flaws in business software, and is not known to use social engineering. Some infrastructure identified by Silent Push was linked to command-and-control activity for malware including the Demodex rootkit and the Snappybee and Ghostspider backdoors. Silent Push reported dozens of previously unreported domains associated with Salt Typhoon and related PRC state-backed actors, identifying 45 domains dating back to at least May 2020. These domains were reportedly registered with fake personas, non-existent U.S. addresses, and ProtonMail accounts, and commonly used .com TLDs and shared name servers including 1domainregistry.com, orderbox-dns.com, monovm.com, and naracauva.com.ru. Some domains were parked, hosted default pages, or later pointed to sinkholes.

The content also notes infrastructure overlap and similar TTPs between Salt Typhoon and UNC4841, a China-linked actor known for exploiting a Barracuda Email Security Gateway zero-day in 2023. Defenders were urged to review historical DNS, telemetry, and log data for related domains and IPs because the actor emphasizes long-term, stealthy access and possible pre-positioning in critical infrastructure and operational technology environments.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNC4841

Salt Typhoon is a Chinese threat actor believed to be operated by the PRC’s Ministry of State Security (MSS). This group has conducted numerous high-profile cyber-espionage campaigns against the United States, as well as against over 80 other countries across the world that are geopolitical competitors with China.

via silentpush blogsilentpush.com
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.