Salt Typhoon is a China-linked state-affiliated cyber espionage threat actor active since at least 2019 and focused primarily on long-term intelligence collection against telecommunications infrastructure. The group is widely tracked under multiple aliases including GhostEmperor, Earth Estries, FamousSparrow, RedMike, Operator Panda, UNC2286, and UNC5807. Public reporting also reflects naming overlap and occasional ambiguity with labels such as KELP and Salt Typhoon-related variants, but Salt Typhoon is the most widely recognized name. The actor is notable for compromising major telecommunications providers and maintaining covert access for extended periods, in some cases for years. Its operations have targeted core telecom environments, including systems associated with lawful-intercept capabilities, with the apparent objectives of intercepting communications, mapping internal networks, collecting configuration and routing data, and preserving strategic access for future intelligence collection or potential disruptive use. Victimology has centered on large telecom operators and related critical communications infrastructure, with reporting also linking the group to intrusions affecting government-connected and defense-relevant environments through telecom access. Salt Typhoon’s tradecraft is distinguished by deep abuse of network infrastructure rather than reliance on conventional endpoint malware. Reported initial access methods include use of valid accounts and, in at least one confirmed case, exploitation of CVE-2018-0171 in Cisco Smart Install. The group has been associated with credential theft and manipulation of network authentication and authorization infrastructure, creation of additional accounts, modification of access controls, and establishment of multiple redundant access paths. Post-compromise activity emphasizes living-off-the-land techniques on routers, switches, and adjacent systems. Observed behaviors include command execution through network device command-line interfaces, activation of Cisco Guest Shell to obtain Linux-level access on supported devices, enabling persistent remote administration channels, collection of running configurations and other device-resident data, use of compromised network devices as pivot points, and traffic duplication or mirroring to support collection. The actor has also used tunneling mechanisms such as GRE and IPsec to move traffic and maintain covert command-and-control paths across compromised infrastructure. Where server-side tooling has been observed, reporting has linked Salt Typhoon to malware and frameworks including GhostSpider, Demodex, SnappyBee, HemiGate, and Cobalt Strike, as well as DLL sideloading through legitimate software. On network devices, the group has been associated with specialized utilities for remote packet capture and collection across chains of compromised devices. Even so, the actor is especially notable for minimizing traditional malware deployment and instead exploiting legitimate device functionality, administrative access, and native management features to reduce detection opportunities. Operationally, Salt Typhoon aligns with broader Chinese intrusion patterns that prioritize stealth, persistence, credential access, discovery, and defense evasion. Comparative ATT&CK-based analyses place the group within a cluster of Chinese espionage actors that share substantial post-compromise behavioral overlap, particularly around valid-account abuse, tool acquisition, network discovery, and indicator removal, although Salt Typhoon is often underrepresented in public datasets because of limited disclosure relative to its apparent capability. Overall, Salt Typhoon represents a high-capability Chinese espionage actor specializing in covert, long-duration compromise of telecommunications and network infrastructure. Its emphasis on infrastructure-level access, lawful-intercept adjacency, credential abuse, and native device functionality makes it particularly significant for telecom operators, governments, and organizations dependent on carrier networks for sensitive communications.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
68 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
34 malware families attributed to this actor across reporting.
29 additional families tracked in Mallory.
24 CVEs this actor has used in observed campaigns. 24 of them exploited in the wild.
The Australian Signals Directorate (ASD) recently issued a high-severity alert about an ongoing cyber attack campaign exploiting a critical vulnerability in Cisco IOS XE devices, tracked as CVE-2023-20198. This vulnerability has a perfect CVSS score of 10.0, reflecting its extreme risk, and has been actively exploited since 2023.
CVE-2018-0171 - активно эксплуатируемая уязвимость (CISA KEV) в функции Smart Install Cisco IOS и IOS XE. CVSS 3.1: 9.8 (CRITICAL)... Атакующий отправляет crafted Smart Install-пакет на TCP-порт 4786 - результат: перезагрузка (DoS) или выполнение произвольного кода.
The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain... ProxyNotShell (CVE-2022-41040, CVE-2022-41082) is a related exploit chain disclosed in 2022. Both allow unauthenticated attackers to execute code on unpatched Exchange servers.
Both groups were also early exploiters of the ProxyLogon vulnerability (CVE-2021-26855) and have used some of the same publicly available tools.
Salt Typhoon has exploited vulnerabilities in Cisco edge devices (notably CVE-2023-20198 and CVE-2023-20273) to gain unauthorized access to telecom networks.
19 more CVEs tied to this actor tracked in Mallory.
160 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked APT focused on long-term covert access in telecommunications and critical infrastructure.
Referenced as an example of a sophisticated state-sponsored threat actor using living-off-the-land style tradecraft to persist in compromised networks and access sensitive government data.
Mentioned only as an example of a current actor lacking MITRE group mapping and requiring manual profiling.
Mentioned only as a comparison point for overlapping techniques with the Russian FSB Center 16-linked activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.