Salt Typhoon, also referred to as Kelp, is a China-linked advanced persistent threat cluster associated with long-term espionage intrusions. The actor has been linked through overlapping tradecraft to other Chinese intrusion sets including Space Pirates and APT41, and attribution is complicated by shared tooling and techniques across these clusters. Reported activity indicates an emphasis on stealthy, persistent access and a particular operational interest in domain controllers and broader enterprise network control. Observed tradecraft includes exploitation attempts against internet-facing services using known remote code execution vulnerabilities, followed by hands-on post-compromise activity to validate connectivity, enumerate network state, and establish persistence. Persistence has included scheduled-task execution chains abusing legitimate Windows build tooling, with subsequent code injection into trusted processes. Salt Typhoon-linked activity has also involved custom in-memory loaders, use of legitimate signed software for DLL sideloading, and deployment patterns consistent with long-term covert access. Additional behavior associated with this cluster includes likely credential theft through DCSync-style abuse of directory replication, indicating an objective of privileged access and durable control inside victim environments. The actor’s tooling and methods fit a broader Chinese state-aligned espionage pattern: use of living-off-the-land binaries, defense evasion through trusted-process abuse, and modular post-exploitation workflows designed to minimize visibility while maintaining operational flexibility. High-confidence reporting ties Kelp to Chinese APT activity, and Salt Typhoon is the most widely recognized name for the cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked intrusion activity associated with DLL sideloading tradecraft using legitimate components to load malicious DLLs for stealthy persistence.
China-linked espionage activity; associated here with DLL sideloading via a legitimate VipreAV component (vetysafe.exe) to load a malicious DLL, and previously linked to telecom compromises and interception of communications tied to the 2024 U.S. presidential election.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.