Salt Typhoon
MITRE ATT&CK: G1045 View on attack.mitre.org
Aliases: Salt Typhoon, OPERATOR PANDA, GhostEmperor, FamousSparrow
- First seen
- 2019-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 18 (3 malicious)
- Last IoC activity
- 2026-07-23 18:48:18
- Profile updated
- 2026-07-07 12:27:42
Targeted industries: technology-and-telecommunications government-and-public-sector
Targeted regions: country_code:us
Context
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).
Recent IoC activity
3 malicious indicators in Maltiverse are attributed to Salt Typhoon (G1045). The 3 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | da692ea0b7f24e31696f8b4fe8a130dbbe3c7c15cea6bde24cccc1fb0a73ae9e | 2026-03-03 | 1 |
| file sample | 8b448f47e36909f3a921b4ff803cf3a61985d8a10f0fe594b405b92ed0fc21f1 | 2026-03-03 | 1 |
| file sample | a1abc3d11c16ae83b9a7cf62ebe6d144dfc5e19b579a99bad062a9d31cf30bfe | 2026-03-03 | 1 |
Detection coverage
- 122 Sigma rules
Malware & tools used
- Clear Linux or Mac System Logs (attack-pattern)
- Network Topology (attack-pattern)
- Protocol Tunneling (attack-pattern)
- Malware (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- SSH Authorized Keys (attack-pattern)
- Network Sniffing (attack-pattern)
- Network Device Configuration Dump (attack-pattern)
- Password Cracking (attack-pattern)
- SSH (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
- Tool (attack-pattern)
- Create Account (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- JumbledPath (malware)
Reports & references
- raw.githubusercontent.com — Microsoftmapping (report)
- MITRE ATT&CK — G1045 (report)
- Cisco Talos — Salt Typhoon Analysis (report)
- home.treasury.gov — Jy2792 (report)