Salt Typhoon is a China-linked, state-sponsored cyberespionage actor associated with the aliases GhostEmperor, Earth Estries, FamousSparrow, RedMike, Operator Panda, UNC2286, and UNC5807. The actor has conducted long-term intrusions against telecommunications providers, government entities, transportation and military-related infrastructure, and organizations providing services to those sectors. Its activity has had a particularly significant focus on U.S. telecommunications infrastructure and has also affected organizations across the Asia-Pacific region, the Middle East, Africa, and other regions. The actor exploits known vulnerabilities in internet-facing appliances and servers, abuses valid credentials, and uses living-off-the-land tools and custom backdoors to establish durable access. Observed tradecraft includes compromising network edge and management infrastructure, collecting network traffic and administrator credentials, conducting reconnaissance and lateral movement through trusted relationships, and exfiltrating communications metadata and other intelligence. Salt Typhoon has targeted telecommunications routing and lawful-intercept environments, enabling access to sensitive communications data and information associated with government officials. The group’s operations are consistent with strategic intelligence collection in support of Chinese state interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
37 malware families attributed to this actor across reporting.
32 additional families tracked in Mallory.
27 CVEs this actor has used in observed campaigns. 27 of them exploited in the wild.
Cisco IOS XE Web UI Privilege Escalation [CVE-2023-20198] ... allows unauthenticated attackers to create a privileged level 15 user account through the Web UI. Combined with CVE-2023-20273, it enables full control over vulnerable Cisco IOS XE devices. RecordedFuture reported observing Salt Typhoon exploiting this vulnerability in a chain along with CVE-2023-20273 ...
CVE-2018-0171 - активно эксплуатируемая уязвимость (CISA KEV) в функции Smart Install Cisco IOS и IOS XE. CVSS 3.1: 9.8 (CRITICAL)... Атакующий отправляет crafted Smart Install-пакет на TCP-порт 4786 - результат: перезагрузка (DoS) или выполнение произвольного кода.
The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain... ProxyNotShell (CVE-2022-41040, CVE-2022-41082) is a related exploit chain disclosed in 2022. Both allow unauthenticated attackers to execute code on unpatched Exchange servers.
ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) A set of four chained vulnerabilities that perform remote code execution (RCE) in Microsoft Exchange servers.
We have observed them exploiting server-based N-day vulnerabilities, including the following: Ivanti Connect Secure VPN Exploitation (CVE-2023-46805 and CVE-2024-21887) A chain of exploits to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges.
22 more CVEs tied to this actor tracked in Mallory.
201 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-linked activity cited as background for a campaign targeting more than 1,000 Cisco network devices.
Referenced as a comparable China-linked threat actor known for compromises of U.S. telecommunications, federal agencies, and critical infrastructure.
Separate Chinese espionage cluster mentioned as a comparison because it collected packet data from compromised routers to harvest administrator credentials across telecommunications networks.
Cyber-espionage activity exploiting known, unpatched vulnerabilities to infiltrate global telecommunications, transportation, and military infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.