TLP:CLEAR
⚠ NATION-STATE · CHINA — MINISTRY OF STATE SECURITY (MSS), CONTRACTOR-ENABLED
// Threat Actor Profile — Telecom & Critical-Infrastructure Cyber Espionage / SIGINT-Enabling Intrusion Group

SALT TYPHOON

PROFILE COMPILED: 2026-08-29  |  SOURCES: MITRE ATT&CK (G1045), CISA/NSA/FBI Joint Advisory, U.S. Treasury/OFAC, Trend Micro (Earth Estries), Recorded Future (RedMike), Wikipedia, therecord.media, Nextgov/FCW, 10+ additional vendor/press sources
Status: ACTIVE — GLOBAL EXPANSION CONTINUING INTO 2026
Threat Level: CRITICAL
Primary Motive: State-Directed Espionage — SIGINT / Communications Collection
Active Since: At least 2019 (core cluster); adjacent activity traced to 2021
MITRE ATT&CK: G1045
⚡ THREAT UPDATE — 2026
Norway confirms compromise as global footprint passes 80 countries
Norway's Police Security Service (PST) confirmed in its 2026 national threat assessment that Salt Typhoon compromised network devices belonging to Norwegian organizations, extending a documented footprint that FBI assessments place at 80+ countries and roughly 600 notified organizations worldwide. The disclosure follows the August 2025 CISA/NSA/FBI joint advisory naming Salt Typhoon (and its Earth Estries/GhostEmperor/UNC2286 aliases) as an active threat to telecommunications and critical infrastructure, and September 2025 U.S. Treasury sanctions against Sichuan Juxinhe Network Technology Co., Ltd. for its direct role supporting the group's US telecom intrusions. Despite sustained diplomatic, sanctions, and advisory pressure, independent honeypot research recorded over 72 million China-origin attack attempts against telecom-emulating decoy systems between August 2023 and August 2025 consistent with Salt Typhoon TTPs, and a suspected Salt Typhoon intrusion into US House national-security committee staff email systems was disclosed in January 2026 — indicating no meaningful reduction in operational tempo.
80+
Countries With Confirmed or Suspected Salt Typhoon Compromises
9
Major US Telecom/ISP Providers Breached (incl. AT&T, Verizon, T-Mobile, Lumen)
1,000+
Cisco Network Devices Targeted in a Single Dec 2024–Jan 2025 Campaign Wave
2019
Earliest Confirmed Activity (Core Cluster)
00
Overview

Salt Typhoon (Microsoft's designation; also tracked as Earth Estries by Trend Micro, GhostEmperor by Kaspersky, FamousSparrow by ESET, UNC2286 by Mandiant, and RedMike by Recorded Future's Insikt Group) is a Chinese state-sponsored cyber-espionage group operating on behalf of China's Ministry of State Security (MSS), active since at least 2019. It became publicly notorious in late 2024 when U.S. officials disclosed that the group had penetrated the core infrastructure of at least nine major American telecommunications and internet-service providers — including AT&T, Verizon, T-Mobile, and Lumen Technologies — in what U.S. intelligence officials characterized as one of the most significant telecommunications intrusions in the nation's history.

What distinguishes Salt Typhoon from most espionage-motivated APT activity is the specific nature of the access it sought: rather than stealing intellectual property or financial data, the group targeted telecom carriers' "lawful intercept" systems — the infrastructure that facilitates court-authorized wiretaps — along with call detail records and customer geolocation data. The FBI confirmed the group accessed communications and metadata belonging to a limited number of predominantly government and political figures, including individuals then associated with the 2024 U.S. presidential campaigns, and copied information about which numbers U.S. law enforcement was actively surveilling.

Salt Typhoon's scale is exceptional even by nation-state standards: FBI and CISA assessments place its confirmed or suspected footprint at more than 80 countries and roughly 600 notified organizations, spanning telecommunications, government, transportation, lodging, and military sectors. Unlike many Chinese APT clusters that operate as uniformed military units, Salt Typhoon's operations have been traced to at least three ostensibly private Chinese technology companies — Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology, and Sichuan Zhixin Ruijie Network Technology — that the U.S. Treasury Department assesses function as contractors providing cyber capabilities directly to Chinese intelligence services, a "state-corporate" operating model increasingly common among Chinese APT groups.

The group remains fully active as of 2026 despite sustained pressure: an August 2025 joint CISA/NSA/FBI advisory, September 2025 Treasury sanctions against Sichuan Juxinhe, and continued congressional oversight have not visibly reduced its operational tempo. New intrusions — including a suspected compromise of U.S. House committee staff email systems handling China policy, foreign affairs, and intelligence oversight, and confirmed compromises in Norway disclosed in that country's 2026 threat assessment — indicate the group continues both to expand geographically and to escalate the sensitivity of its targeting.

01
Identity & Attribution
Primary NameSalt Typhoon
Sponsor / ParentChina's Ministry of State Security (MSS); operationally supported by at least three MSS-linked contractor companies (Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology, Sichuan Zhixin Ruijie Network Technology)
Actor TypeNation-State — Contractor-Enabled Cyber Espionage / SIGINT-Enabling Intrusion Group
Primary MotivationState-directed intelligence collection — communications/SIGINT access, government and political-figure surveillance, strategic-infrastructure reconnaissance
Active SinceAt least 2019 (core Salt Typhoon cluster); adjacent Earth Estries/GhostEmperor activity traced to 2021 by some vendors
Last Observed2026 — confirmed compromise disclosed in Norway's 2026 national threat assessment; suspected involvement in a Dec 2025/Jan 2026 US House committee staff email intrusion
MITRE G-IDG1045
Legal StatusUS Treasury/OFAC sanctioned Sichuan Juxinhe Network Technology Co., Ltd. (Sep 2025) for direct involvement in the group's US telecom breaches, and separately sanctioned Shanghai-based cyber actor Yin Kecheng (Jan 2025) for the related US Treasury network compromise. No criminal indictment has been unsealed against named Salt Typhoon operators specifically as of this writing.
Tracking Aliases
Salt Typhoon Earth Estries GhostEmperor FamousSparrow UNC2286 RedMike
Attribution Confidence

HIGH on state sponsorship. US government agencies (FBI, CISA, NSA, Treasury/OFAC) and multiple independent vendors (Microsoft, Trend Micro, Kaspersky, ESET, Mandiant, Recorded Future) converge on attributing this activity cluster to Chinese state sponsorship via the Ministry of State Security, corroborated by Treasury's formal sanctions designation of a specific contractor company. Confidence in the precise institutional chain is MEDIUM — which MSS bureau directly taskes the contractor companies, and how cleanly "Salt Typhoon" separates from adjacent clusters like GhostEmperor/Earth Estries at the level of individual personnel, remains an open question reflecting the loosely federated, contractor-based structure increasingly typical of Chinese cyber operations. Note: separate March 2025 DOJ indictments of individuals named "Yin Kecheng" and "Zhou Shuai" concern APT27-linked hacking-for-hire activity; public reporting has not conclusively resolved whether this is the same Yin Kecheng sanctioned for the Salt Typhoon/Treasury intrusion — an acknowledged gap in this profile rather than a confirmed link.

02
Campaign & Operational Timeline
2019
Earliest Confirmed Activity
Microsoft and US government assessments place the earliest confirmed Salt Typhoon activity in 2019; overlapping GhostEmperor/Earth Estries clusters are separately documented by some vendors from 2021 onward, reflecting the difficulty of cleanly separating adjacent Chinese contractor-operated clusters.
2021 –
2023
Global Telecom & Government Espionage Buildout
Group (tracked by various vendors as Earth Estries/GhostEmperor) conducts long-term espionage campaigns against telecommunications and government networks across the Asia-Pacific region, Middle East, and Africa, developing and refining custom malware including Demodex and SnappyBee.
DEC 2024
US Telecom Breach Disclosed
US officials disclose that Salt Typhoon penetrated at least nine major US telecom/ISP providers, including AT&T, Verizon, T-Mobile, and Lumen Technologies, compromising lawful-intercept wiretap infrastructure, call records, and geolocation data affecting government and political figures.
DEC 2024 –
JAN 2025
Mass Cisco Device Exploitation Campaign
Group attempts exploitation of 1,000+ internet-facing Cisco network devices worldwide (more than half in the US, South America, and India) via CVE-2023-20198/CVE-2023-20273 and the seven-year-old CVE-2018-0171, tracked by Recorded Future as "RedMike."
JAN 2025
Treasury Sanctions & Related Compromise Disclosures
OFAC sanctions Shanghai-based actor Yin Kecheng for a related compromise of the US Treasury Department's own network, including senior official workstations and bank-regulator email accounts.
AUG –
SEP 2025
Joint Advisory & Corporate Sanctions
CISA, NSA, and FBI (with international partners) issue a joint cybersecurity advisory on Salt Typhoon/Earth Estries/GhostEmperor activity; Treasury separately sanctions Sichuan Juxinhe Network Technology Co., Ltd. for direct involvement in the telecom breaches.
LATE 2025 –
2026
Continued Expansion — Congress & Norway
A suspected Salt Typhoon intrusion into email systems used by US House committee staff overseeing China policy, foreign affairs, intelligence, and the military is disclosed (Jan 2026); Norway's Police Security Service confirms compromises of Norwegian organizations in its 2026 national threat assessment, underscoring the group's continued global reach.
03
Attack Lifecycle Living off network devices — minimal malware footprint on carrier-grade infrastructure

Salt Typhoon's initial access is dominated by exploitation of known, often long-unpatched vulnerabilities in internet-facing network edge devices rather than novel zero-days or social engineering. The group has weaponized a seven-year-old flaw in Cisco's IOS Smart Install feature (CVE-2018-0171) and chained a 2023 Cisco IOS XE web-UI privilege-escalation bug with a companion root-access flaw (CVE-2023-20198/CVE-2023-20273) to compromise carrier-grade routers and switches directly, alongside documented exploitation of vulnerabilities in Ivanti Connect Secure VPN, Fortinet FortiClient EMS, Sophos firewalls, and Microsoft Exchange in adjacent Earth Estries campaigns.

Once on a device, the group favors "living off the land" on network infrastructure itself rather than deploying conventional endpoint malware: dumping device configuration files to harvest weakly encrypted stored credentials, brute-forcing what it recovers, adding SSH authorized_keys entries and creating new Linux-level accounts directly in /etc/shadow and /etc/passwd for durable, credential-independent persistence, and altering Access Control Lists and loopback interface addresses to bypass network segmentation controls. Where custom tooling is deployed, it is purpose-built for the carrier environment — the JumbledPath utility handles archiving, log-clearing, infrastructure hiding, and multi-stage covert communications, while modular backdoors like GhostSpider, the Demodex rootkit, and the shared Chinese-APT tool SnappyBee provide flexible, victim-tailored capability.

The group's ultimate objective — access to lawful-intercept and call-detail infrastructure — is achieved through direct network sniffing between compromised device interfaces and the establishment of covert GRE tunnels that let operators pivot deep into carrier backbones while evading conventional network monitoring. Exfiltration of harvested configuration data typically leaves the network over unencrypted FTP/TFTP sessions rather than a distinct C2 channel, blending with legitimate device-management traffic and complicating detection in environments where network device logging and monitoring are historically underinvested compared to endpoint security.

04
TTPs — MITRE ATT&CK Mapping Enterprise framework; mapped against G1045
Reconnaissance
T1590
Gather Victim Network Information: Network Topology
[HIGH] Parsed stolen network device configuration files to map upstream/downstream segments and identify high-value pivot points.
Resource Development
T1587.001
Develop Capabilities: Malware
[HIGH] Developed custom tooling including JumbledPath for archiving, log-clearing, infrastructure hiding, and multi-stage C2.
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] Exploited a seven-year-old flaw (CVE-2018-0171) in Cisco IOS Smart Install to gain initial footholds on telecom edge routers.
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] Chained CVE-2023-20198 (Cisco IOS XE web-UI privilege escalation) with CVE-2023-20273 to obtain root access on 1,000+ targeted devices.
Credential Access
T1110.002
Brute Force: Password Cracking
[MEDIUM] Cracked weakly encrypted passwords recovered from stolen network device configuration files.
Persistence
T1098.004
Account Manipulation: SSH Authorized Keys
[HIGH] Added SSH authorized_keys entries under root and other accounts on compromised network devices for durable, credential-independent access.
Persistence
T1136
Create Account
[MEDIUM] Modified /etc/shadow and /etc/passwd directly to create new Linux-level user accounts on compromised devices.
Defense Evasion
T1685
Disable or Modify Tools: Clear Logs
[HIGH] Cleared .bash_history, auth.log, lastlog, wtmp, and btmp to erase forensic evidence of access.
Defense Evasion
T1686
Disable or Modify System Firewall
[MEDIUM] Altered Access Control Lists and loopback interface addresses on network devices to bypass restrictions and evade detection.
Lateral Movement
T1021.004
Remote Services: SSH
[HIGH] Modified loopback interface addresses to bypass ACL restrictions and pivot laterally between network segments via SSH.
Command & Control
T1572
Protocol Tunneling
[HIGH] Established Generic Routing Encapsulation (GRE) tunnels via device configuration changes for covert, persistent network paths.
Collection
T1040
Network Sniffing
[HIGH] Captured live packet data between compromised network device interfaces, directly enabling access to call content, metadata, and lawful-intercept systems.
Exfiltration
T1048.003
Exfiltration Over Alternative Protocol: Unencrypted Non-C2 Protocol
[MEDIUM] Exfiltrated stolen device configuration files via FTP and TFTP, blending with legitimate device-management traffic.
05
Targeting Profile
Sector Targeting
Telecommunications
PRIMARY
ISPs / Network Infrastructure Operators
HIGH
Government & Public Administration
HIGH
Transportation & Lodging
MED
Military & Defense-Adjacent
MED
GeographiesGlobal — confirmed or suspected compromises across 80+ countries; concentrated targeting of the United States, with confirmed activity also disclosed in Norway (2026), Canada, and across Asia-Pacific, the Middle East, and Africa under the group's Earth Estries/GhostEmperor activity
Victim ProfileTelecom carriers and ISPs operating lawful-intercept/wiretap infrastructure; government agencies and legislative bodies with national-security or China-policy portfolios; organizations running internet-facing, historically under-patched network edge devices
Preferred EntryExploitation of known (often years-old) CVEs in carrier-grade and enterprise network edge devices — routers, VPN appliances, firewalls — rather than phishing or supply-chain compromise
Target DoctrineSystematic, infrastructure-first targeting aimed at durable SIGINT-style access to communications backbones and the specific legal-surveillance systems designed to protect against unauthorized access — infrastructure capture for long-term intelligence collection, not opportunistic data theft
06
Tools, Malware & Infrastructure
GhostSpider Modular Backdoor · Custom
Highly modular, victim-tailored backdoor capable of exfiltrating data, loading additional malicious modules on demand, and self-removing from memory to increase stealth; functions are triggered remotely via C2 instructions, letting operators adapt capability per target without redeploying core malware.
Demodex Rootkit · Custom
A kernel-level rootkit used to conceal the group's presence on compromised Windows and Linux hosts, deployed alongside GhostSpider and SnappyBee in long-term espionage campaigns against government and telecom targets across Asia-Pacific.
SnappyBee Modular Backdoor · Shared Chinese-APT Tooling
A modular backdoor observed across multiple Chinese state-linked intrusion sets, indicating shared tooling and infrastructure-development resources within China's contractor-based cyber ecosystem rather than a tool unique to Salt Typhoon alone.
JumbledPath Custom Utility · MITRE S1206
Purpose-built tool for archiving collected data, clearing logs, hiding infrastructure, and conducting multi-stage covert communications and network sniffing — reflecting the group's emphasis on operating discreetly within carrier-grade network device environments rather than on conventional endpoints.
Masol RAT Linux Backdoor
A Linux-targeting remote access trojan used in campaigns against government and telecom infrastructure, extending the group's capability beyond Windows-centric tooling to the Linux-based network appliances that dominate carrier environments.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 10 are NOT defanged.
Type Value / Description Source Date
CVECVE-2018-0171 — Cisco IOS Smart Install remote code executionCisco Talos / CISADisclosed 2018; exploited 2024–2025
CVECVE-2023-20198 — Cisco IOS XE Web UI privilege escalation (initial access)Cisco / CISA KEVDisclosed 2023-10; exploited Dec 2024–Jan 2025
CVECVE-2023-20273 — Cisco IOS XE root-access flaw (chained with above)Cisco / CISA KEVDisclosed 2023-10; exploited Dec 2024–Jan 2025
MALWAREJumbledPath, GhostSpider, Demodex, SnappyBee, Masol RATTrend Micro; Recorded Future; CISA/NSA/FBI joint advisory2024–2025
SANCTIONED ENTITYSichuan Juxinhe Network Technology Co., Ltd.US Treasury / OFAC2025-09
NOTENo durable static IP/domain indicator list is included here. Salt Typhoon compromises carrier-owned network devices directly, and its infrastructure (compromised routers, hop points) is victim-specific and rotates constantly. Consult the August 2025 CISA/NSA/FBI joint advisory and named vendor reporting (Recorded Future "RedMike," Trend Micro "Earth Estries") for current, environment-specific indicators rather than a static list reproduced here.
08
Analyst Assessment
Overall Threat LevelCRITICAL
Attribution ConfidenceHIGH (state sponsorship) / MEDIUM (precise inter-cluster boundaries)
TrajectoryEscalating — continued geographic expansion (Norway, 2026), continued targeting escalation (US congressional committee staff), no observed reduction in tempo despite sanctions and advisories
Most Dangerous CapabilityDurable, credential-independent persistence directly on carrier-grade network infrastructure, providing SIGINT-equivalent access to communications content, metadata, and lawful-intercept systems
Primary Intel GapFull scope of ongoing access inside already-notified US carriers — AT&T and Verizon state they evicted the group, but a US Senator and independent researchers have publicly questioned whether eviction is complete, given reportedly withheld third-party forensic reports
Ecosystem / Affiliated Groups
Earth Estries GhostEmperor FamousSparrow UNC2286 RedMike MSS contractor ecosystem (Sichuan Juxinhe, Beijing Huanyu Tianqiong, Sichuan Zhixin Ruijie)

Salt Typhoon represents a doctrinal shift that should concern defenders beyond the telecom sector specifically: rather than treating network infrastructure devices as plumbing to be patched opportunistically, this group treats routers, VPN concentrators, and firewalls as the primary target — the place where durable, high-value access lives — and has demonstrated it can operate there for extended periods with minimal reliance on conventional, more heavily monitored endpoint malware. Its specific interest in lawful-intercept systems is a notable escalation: it targets not just communications but the infrastructure meant to safeguard those communications' legal-authorization boundaries, giving a foreign intelligence service potential visibility into who US law enforcement is investigating.

The group's contractor-based operating model — MSS tasking ostensibly private companies like Sichuan Juxinhe rather than uniformed military units — mirrors a broader trend across Chinese state-sponsored activity and complicates both attribution and disruption: sanctioning or even successfully prosecuting one contractor company does not necessarily remove the underlying MSS tasking relationship or the pool of technical talent available to service it. This helps explain why sustained diplomatic and legal pressure through 2025 has not visibly reduced Salt Typhoon's operational tempo into 2026.

Confidence in this assessment would increase with independently verified confirmation that named US carriers have fully evicted the group — currently a contested claim given Senate inquiries into withheld third-party forensic reports — and would improve if the September 2025 sanctions or a future criminal indictment meaningfully disrupted the specific contractor relationships enabling the group's edge-device tooling pipeline. The clearest forward risk is further escalation up the sensitivity ladder: having already reached telecom wiretap systems, a federal agency network (Treasury), and now congressional committee staff email, further targeting of comparably sensitive US government functions should be treated as a realistic near-term possibility rather than a worst-case outlier.

09
Defensive Recommendations
01
Patch and inventory internet-facing network edge devices as a first-class asset class. Treat routers, VPN concentrators, and firewalls with the same patch-SLA rigor as internet-facing servers; specifically verify remediation of CVE-2018-0171, CVE-2023-20198, and CVE-2023-20273 on all Cisco IOS/IOS XE devices.
Counters: T1190
02
Disable unnecessary device-management interfaces and services. Disable the Cisco Smart Install feature and internet-exposed web UI management interfaces where not explicitly required; restrict management-plane access to out-of-band networks.
Counters: T1190
03
Harden and monitor device configuration storage and access. Encrypt stored device credentials rather than relying on weak/reversible encoding, and alert on bulk configuration-file access or export events.
Counters: T1602, T1110.002
04
Monitor for unauthorized SSH key and account changes on network devices. Baseline and alert on any modification to SSH authorized_keys files or /etc/shadow and /etc/passwd on routers, switches, and appliances.
Counters: T1098.004, T1136
05
Centralize and protect device logs off-device. Forward syslog, auth.log, and command-history data to a centralized, access-controlled logging platform immediately upon generation, since on-device log-clearing only works if logs remain solely on the compromised device.
Counters: T1685
06
Audit ACL and loopback interface configuration changes. Implement configuration-drift detection on network devices to flag unauthorized ACL or loopback-address modifications that could indicate segmentation bypass.
Counters: T1686, T1021.004
07
Monitor for anomalous GRE tunnels and unencrypted bulk transfers. Alert on newly established GRE tunnels not present in change-management records, and restrict or monitor FTP/TFTP usage on network infrastructure, which legitimate operations rarely require post-provisioning.
Counters: T1572, T1048.003
08
Extend the highest access-control tier to lawful-intercept infrastructure. Apply enhanced access control, logging, and anomaly detection specifically to lawful-intercept/CALEA systems, treating them as a distinct high-sensitivity zone rather than ordinary carrier backbone.
Counters: T1040
10
References URLs are NOT defanged — navigate directly
MITRE ATT&CK
Accessed: 2026-08-29
Wikipedia
Accessed: 2026-08-29
Recorded Future
Accessed: 2026-08-29
BankInfoSecurity
Accessed: 2026-08-29