Salt Typhoon is a China-linked state-sponsored espionage threat actor focused on long-term, covert compromise of telecommunications and related network infrastructure. The group has been active since at least 2019 and is associated with sustained cyber-espionage operations against major telecom providers, government entities, transportation, lodging, and military networks. Reported aliases include GhostEmperor, Earth Estries, FamousSparrow, RedMike, Operator Panda, UNC2286, and UNC5807, although some of these names have been used inconsistently across reporting and may reflect overlapping or evolving cluster designations. Salt Typhoon is notable for intrusions into major U.S. telecommunications providers and for compromising systems associated with lawful intercept capabilities. Its operations emphasize surveillance, communications interception, internal network mapping, and prepositioning for future access. In telecom environments, the actor has demonstrated the ability to maintain access for years while minimizing malware deployment and instead abusing legitimate network-device functionality. Observed tradecraft includes initial access through valid accounts and, in at least one confirmed case, exploitation of CVE-2018-0171 in Cisco Smart Install. The actor has used compromised administrative credentials, modified AAA-related configurations, created additional accounts, altered access controls, enabled Cisco Guest Shell, exposed SSH services on nonstandard ports, and used compromised network devices as pivot points. Collection and exfiltration methods have included harvesting device configurations, remote packet capture, traffic mirroring via SPAN or ERSPAN, and tunneling through GRE or IPsec. Server-side tooling associated with the actor includes GhostSpider, Demodex, SnappyBee, HemiGate, Cobalt Strike, and the Go-based JumbledPath utility, as well as DLL sideloading through legitimate software. The group’s operational profile is consistent with strategic intelligence collection rather than financially motivated crime. Its targeting of telecom carriers, sensitive communications, and national-security-relevant infrastructure aligns with Chinese state espionage objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
68 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
34 malware families attributed to this actor across reporting.
29 additional families tracked in Mallory.
24 CVEs this actor has used in observed campaigns. 24 of them exploited in the wild.
The Australian Signals Directorate (ASD) recently issued a high-severity alert about an ongoing cyber attack campaign exploiting a critical vulnerability in Cisco IOS XE devices, tracked as CVE-2023-20198. This vulnerability has a perfect CVSS score of 10.0, reflecting its extreme risk, and has been actively exploited since 2023.
CVE-2018-0171 - активно эксплуатируемая уязвимость (CISA KEV) в функции Smart Install Cisco IOS и IOS XE. CVSS 3.1: 9.8 (CRITICAL)... Атакующий отправляет crafted Smart Install-пакет на TCP-порт 4786 - результат: перезагрузка (DoS) или выполнение произвольного кода.
The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain... ProxyNotShell (CVE-2022-41040, CVE-2022-41082) is a related exploit chain disclosed in 2022. Both allow unauthenticated attackers to execute code on unpatched Exchange servers.
Both groups were also early exploiters of the ProxyLogon vulnerability (CVE-2021-26855) and have used some of the same publicly available tools.
Salt Typhoon has exploited vulnerabilities in Cisco edge devices (notably CVE-2023-20198 and CVE-2023-20273) to gain unauthorized access to telecom networks.
19 more CVEs tied to this actor tracked in Mallory.
160 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of a Chinese government-linked cyber espionage campaign involving breaches of numerous US telecommunications companies.
State-sponsored cyber campaign involving the compromise of U.S. telecommunications companies; the report discusses possible pathways and infrastructure links involving Chinese telecom carriers that may have supported or enabled the activity.
Espionage campaign referenced in connection with U.S.-based network links and routing infrastructure that could sustain malicious infrastructure and provide visibility into sensitive U.S. network traffic.
Conducted a broad espionage campaign against telecom carriers, breaching systems used for lawful intercept/wiretap compliance and targeting communications of senior U.S. officials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.