Salt Typhoon is a China-linked state-sponsored cyberespionage threat actor associated across reporting with the aliases GhostEmperor, Earth Estries, FamousSparrow, RedMike, UNC2286, and UNC5807. The cluster is best known for long-running espionage operations against telecommunications providers and government environments, including major compromises of U.S. telecommunications infrastructure, and has also been linked to activity affecting universities, technology organizations, and other critical infrastructure targets worldwide. The actor’s operations emphasize intelligence collection rather than disruption or monetization. Reported tradecraft includes systematic exploitation of internet-facing edge infrastructure and network appliances, especially public-facing web interfaces on Cisco IOS XE devices and flaws in products such as Ivanti Connect Secure, Sophos Firewall, and Fortinet FortiClient EMS. In multiple campaigns, the group exploited known vulnerabilities to obtain initial access and elevated privileges on network devices, then modified device configurations and established GRE tunnels to maintain covert access and support data theft. Other reporting indicates the actor has also used valid or stolen credentials in some Cisco-related intrusions, underscoring a flexible approach to compromising edge infrastructure. Salt Typhoon has been described as highly capable and stealth-focused. Observed behaviors include exploitation of public-facing applications, credential theft, network sniffing, privilege escalation, lateral movement, persistence through service creation and configuration changes, covert exfiltration, and use of custom malware and command-and-control infrastructure. Detection content and incident reporting also associate the cluster with living-off-the-land techniques, log suppression or disabling, and avoidance of traditional malware on some network-device compromises. In Windows intrusions attributed or suspected to be linked to GhostEmperor, reporting has described DLL side-loading, process hollowing, reconnaissance, LSASS dumping, searches for domain credential material, archival of collected data, and exfiltration to external services. Targeting has been especially prominent in the telecommunications sector, where the actor has compromised carriers and internet service providers to access communications and sensitive network data. Public reporting also places its victims in government and public-sector organizations, technology entities, universities, and broader critical infrastructure. Countries explicitly associated with targeting include the United States, the Philippines, Taiwan, Malaysia, South Africa, Germany, Indonesia, and Vietnam. The naming and clustering around Salt Typhoon, GhostEmperor, Earth Estries, and FamousSparrow are not uniform across vendors, but the supplied reporting repeatedly treats these names as the same actor or closely overlapping operational cluster. At high confidence, the actor is best characterized as a PRC-linked espionage group focused on strategic intelligence collection through compromise of telecommunications and other internet-facing critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
35 malware families attributed to this actor across reporting.
30 additional families tracked in Mallory.
25 CVEs this actor has used in observed campaigns. 25 of them exploited in the wild.
Cisco IOS XE Web UI Privilege Escalation [CVE-2023-20198] ... allows unauthenticated attackers to create a privileged level 15 user account through the Web UI. Combined with CVE-2023-20273, it enables full control over vulnerable Cisco IOS XE devices. RecordedFuture reported observing Salt Typhoon exploiting this vulnerability in a chain along with CVE-2023-20273 ...
CVE-2018-0171 - активно эксплуатируемая уязвимость (CISA KEV) в функции Smart Install Cisco IOS и IOS XE. CVSS 3.1: 9.8 (CRITICAL)... Атакующий отправляет crafted Smart Install-пакет на TCP-порт 4786 - результат: перезагрузка (DoS) или выполнение произвольного кода.
The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain... ProxyNotShell (CVE-2022-41040, CVE-2022-41082) is a related exploit chain disclosed in 2022. Both allow unauthenticated attackers to execute code on unpatched Exchange servers.
Both groups were also early exploiters of the ProxyLogon vulnerability (CVE-2021-26855) and have used some of the same publicly available tools.
CVE-2023-20273: Vulnerability Type: Command Injection ... allows an authenticated attacker to perform command injection with root privileges. Combined with CVE-2023-20198, it enables full control over vulnerable Cisco IOS XE devices. RecordedFuture reported observing Salt Typhoon exploiting this vulnerability in a chain along with CVE-2023-20273 ...
20 more CVEs tied to this actor tracked in Mallory.
185 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese state-sponsored cyberespionage campaign targeting telecommunications companies and telecommunications infrastructure, including U.S. telecommunications providers, with related activity affecting multiple countries.
State-sponsored cyberespionage campaign tied to compromises of at least nine U.S. telecommunications operators, with technical links discussed in relation to Chinese telecom infrastructure.
Referenced as an example of a Chinese government-linked cyber espionage campaign involving breaches of numerous US telecommunications companies.
State-sponsored cyber campaign involving the compromise of U.S. telecommunications companies; the report discusses possible pathways and infrastructure links involving Chinese telecom carriers that may have supported or enabled the activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.