GhostEmperor is a China-linked cyberespionage tracking name associated with the broader Salt Typhoon campaign against telecommunications and other strategically important networks. The activity is attributed to People's Republic of China state-sponsored operators. Related tracking labels include Earth Estries, OPERATOR PANDA, RedMike, UNC2286 and UNC5807, although these designations describe overlapping activity and are not uniformly established as exact synonyms. FamousSparrow has also been associated with Salt Typhoon, but remains separately tracked by ESET because technical evidence is insufficient to establish equivalence. The campaign prioritizes telecommunications providers and internet service providers, alongside government and technology organizations. Associated network-infrastructure operations also target transportation, lodging and military organizations. Documented activity spans the United States, Canada, Australia, New Zealand and the United Kingdom. Espionage objectives include stealing customer call records, intercepting selected private communications and gathering intelligence on government officials and politically involved individuals. At least nine U.S. telecommunications providers were breached, and access persisted for more than three years in some cases. Operators exploit known vulnerabilities in internet-facing routers, firewalls, VPN gateways and enterprise applications. Documented exploitation includes Cisco vulnerabilities CVE-2018-0171 and CVE-2023-20198, as well as vulnerabilities affecting Microsoft Exchange, Sophos, Fortinet and Ivanti products. They maintain access through configuration changes, privileged accounts, tunneling and custom malware, including GhostSpider, SnappyBee and Masol. GRE tunnels and native packet-capture capabilities support traffic collection and exfiltration. Associated operations harvest authentication credentials, pivot through trusted network connections, abuse native scripting and management interfaces, and manipulate routing, authentication settings and logs to conceal persistent access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
29 malware families attributed to this actor across reporting.
24 additional families tracked in Mallory.
26 CVEs this actor has used in observed campaigns. 26 of them exploited in the wild.
According to ESET telemetry, FamousSparrow started to exploit the vulnerabilities the day following Microsoft’s release of a patch for the problem. In FamousSparrow’s case, it used the bug to deploy SparrowDoor.
Cyber actors are installing an implant dubbed ‘BADCANDY’ on Cisco IOS XE devices that are vulnerable to CVE-2023-20198. ASD is aware of ongoing exploitation.
Static Tundra has been exploiting CVE-2018-0171, a CVSS 9.8 Cisco Smart Install vulnerability, to compromise unpatched network devices worldwide for intelligence gathering. The content also reports that Salt Typhoon leveraged this vulnerability against major U.S. telecommunications companies.
CVE-2024-21887 is listed as an 'Ivanti Connect Secure and Ivanti Policy Secure Command Injection Vulnerability' exploited by Salt Typhoon.
The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain... ProxyNotShell (CVE-2022-41040, CVE-2022-41082) is a related exploit chain disclosed in 2022. Both allow unauthenticated attackers to execute code on unpatched Exchange servers.
21 more CVEs tied to this actor tracked in Mallory.
400 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with breaches of U.S. and global telecommunications networks. Its operations informed the Taiwan war-game scenario; the article does not attribute an actual attack on Taiwan to this actor.
A Chinese hacking campaign that breached telecommunications networks in the United States and elsewhere. Its operations informed the Taiwan war game's communications-disruption scenario, although the exercise packets did not name it directly.
Chinese state-sponsored group described as compromising organizations worldwide, including US telecommunications carriers, and maintaining prolonged access to collect communications data. The article presents this activity as an example of harvesting encrypted data for potential future quantum-enabled decryption.
Referenced in passing as an example of a cyberattack against US telecommunications networks, illustrating that excluding Chinese vendors would not by itself eliminate technical security risks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.