Salt Typhoon

MITRE ATT&CK: G1045 View on attack.mitre.org

Aliases: Salt Typhoon, OPERATOR PANDA, GhostEmperor, FamousSparrow

First seen
2019-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
18 (3 malicious)
Last IoC activity
2026-07-23 18:48:18
Profile updated
2026-07-07 12:27:42

Targeted industries: technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:us

Context

Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).

Recent IoC activity

3 malicious indicators in Maltiverse are attributed to Salt Typhoon (G1045). The 3 most recently updated:

Detection coverage

  • 122 Sigma rules

Malware & tools used

  • Clear Linux or Mac System Logs (attack-pattern)
  • Network Topology (attack-pattern)
  • Protocol Tunneling (attack-pattern)
  • Malware (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • SSH Authorized Keys (attack-pattern)
  • Network Sniffing (attack-pattern)
  • Network Device Configuration Dump (attack-pattern)
  • Password Cracking (attack-pattern)
  • SSH (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)
  • Tool (attack-pattern)
  • Create Account (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • JumbledPath (malware)

Reports & references

  • raw.githubusercontent.com — Microsoftmapping (report)
  • MITRE ATT&CK — G1045 (report)
  • Cisco Talos — Salt Typhoon Analysis (report)
  • home.treasury.gov — Jy2792 (report)

External references