Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Salt Typhoon

Also known as: FamousSparrow, UNC2286, Salt Typhoon, RedMike, OPERATOR PANDA

Description

Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).(Citation: US Dept. of Treasury Salt Typhoon JAN 2025)(Citation: Cisco Salt Typhoon FEB 2025)

AI Analysis

· 1 week ago

Executive Summary

Salt Typhoon, a state-backed Chinese cyber threat actor, has targeted U.S. telecommunication and internet service providers since at least 2019. Notably linked to sophisticated attacks leveraging malware and network exploitation techniques, their primary focus appears to be compromising critical infrastructure for potential economic or strategic advantage.

Goals & Targeting

Salt Typhoon's primary goal appears to be compromising critical infrastructure within the U.S., particularly in the telecommunications sector. Their targeting profile indicates an interest in sectors that underpin national communication and internet services. The group likely seeks to achieve strategic advantages through these compromises, potentially for espionage or economic gain. U.S. telecommunication and ISP companies are their primary targets, suggesting a focus on infrastructure that could have wide-reaching implications.

Enhanced Description

Salt Typhoon is a cyber threat actor known to operate under the auspices of the People's Republic of China. They have been active since at least 2019 and are primarily associated with compromising network infrastructure, particularly targeting major U.S. telecommunication and internet service providers (ISPs). The group has demonstrated advanced capabilities in exploiting network devices and protocols, employing techniques such as network sniffing, protocol tunneling, and password cracking. The actor's operations suggest a focus on long-term strategic interests, possibly for intelligence gathering or disruption purposes.

Key Capabilities

  • Network Exploitation
  • Malware Development
  • Password Cracking
  • SSH Tunneling
  • Defense Evasion Techniques

MITRE ATT&CK Tactics

Credential Access
Defense Evasion
Discovery
Lateral Movement
Network Sharing
Exfiltration
Collection
Impact

ATT&CK Techniques

T1110.002
T1587.001
T1021.004
T1040
T1590.004
T1136
T1572
T1685.006
T1588.002
T1098.004

Software / Tooling

JumbledPath

Campaigns & Victims

Salt Typhoon's campaigns have focused on infiltrating and compromising the network infrastructure of major U.S. telecommunication and ISP companies. Their operational tactics include persistent network access, data exfiltration, and potential long-term presence within targeted networks. Notable past operations involve targeted attacks that exploit specific vulnerabilities in network devices, leveraging tools like JumbledPath for malicious activities.

IOC Patterns

  • Network traffic异常 with SSH protocol usage
  • SMB协议或HTTP的非正常通信模式
  • 网络设备配置dump活动
  • 网络嗅探和横向移动迹象

Recommended Actions

  • Implement enhanced network monitoring for unusual traffic patterns, especially over SSH and SMB protocols.
  • Apply multi-factor authentication to critical systems and services.
  • Conduct regular software updates and patches on all network devices。
  • Restrict access to sensitive networks from external sources
  • Deploy network segmentation to isolate critical infrastructure components.

Suggested Tags

APT
China-state_backed
Telecommunications_Sector
Infrastructure_Targeting

Confidence Assessment

High confidence in Salt Typhoon's state-backed affiliation and targeting of U.S. telecommunication sectors, supported by U.S. Department of the Treasury and Cisco reports. However, specific TTP sequences tied to individual campaigns remain unclear.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Cisco Salt Typhoon FEB 2025 — Cisco Talos. (2025, February 20). Weathering the storm: In the midst of a Typhoon. Retrieved February 24, 2025.
  2. US Dept. of Treasury Salt Typhoon JAN 2025 — US Department of Treasury. (2025, January 17). Treasury Sanctions Company Associated with Salt Typhoon and Hacker Associated with Treasury Compromise. Retrieved February 24, 2025.

Intel Summary

14

Techniques

1

Tools

0

Campaigns

5

IOCs

0

Observed Data

10

Tactics

Tags

APT
China-state_backed
Telecommunications_Sector
Infrastructure_Targeting

Details

MITRE ID
G1045
Type
Unknown
Country of Origin
C
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--1c3dcf91-b859-4aae-a09c-ae26dc8b6390
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.