Also known as: FamousSparrow, UNC2286, Salt Typhoon, RedMike, OPERATOR PANDA
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).(Citation: US Dept. of Treasury Salt Typhoon JAN 2025)(Citation: Cisco Salt Typhoon FEB 2025)
Executive Summary
Salt Typhoon, a state-backed Chinese cyber threat actor, has targeted U.S. telecommunication and internet service providers since at least 2019. Notably linked to sophisticated attacks leveraging malware and network exploitation techniques, their primary focus appears to be compromising critical infrastructure for potential economic or strategic advantage.
Goals & Targeting
Salt Typhoon's primary goal appears to be compromising critical infrastructure within the U.S., particularly in the telecommunications sector. Their targeting profile indicates an interest in sectors that underpin national communication and internet services. The group likely seeks to achieve strategic advantages through these compromises, potentially for espionage or economic gain. U.S. telecommunication and ISP companies are their primary targets, suggesting a focus on infrastructure that could have wide-reaching implications.
Enhanced Description
Salt Typhoon is a cyber threat actor known to operate under the auspices of the People's Republic of China. They have been active since at least 2019 and are primarily associated with compromising network infrastructure, particularly targeting major U.S. telecommunication and internet service providers (ISPs). The group has demonstrated advanced capabilities in exploiting network devices and protocols, employing techniques such as network sniffing, protocol tunneling, and password cracking. The actor's operations suggest a focus on long-term strategic interests, possibly for intelligence gathering or disruption purposes.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Salt Typhoon's campaigns have focused on infiltrating and compromising the network infrastructure of major U.S. telecommunication and ISP companies. Their operational tactics include persistent network access, data exfiltration, and potential long-term presence within targeted networks. Notable past operations involve targeted attacks that exploit specific vulnerabilities in network devices, leveraging tools like JumbledPath for malicious activities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Salt Typhoon's state-backed affiliation and targeting of U.S. telecommunication sectors, supported by U.S. Department of the Treasury and Cisco reports. However, specific TTP sequences tied to individual campaigns remain unclear.
No campaigns linked yet.
No observed data linked yet.
14
Techniques
1
Tools
0
Campaigns
5
IOCs
0
Observed Data
10
Tactics