Salt Typhoon (Microsoft's designation; also tracked as Earth Estries by Trend Micro, GhostEmperor by Kaspersky, FamousSparrow by ESET, UNC2286 by Mandiant, and RedMike by Recorded Future's Insikt Group) is a Chinese state-sponsored cyber-espionage group operating on behalf of China's Ministry of State Security (MSS), active since at least 2019. It became publicly notorious in late 2024 when U.S. officials disclosed that the group had penetrated the core infrastructure of at least nine major American telecommunications and internet-service providers — including AT&T, Verizon, T-Mobile, and Lumen Technologies — in what U.S. intelligence officials characterized as one of the most significant telecommunications intrusions in the nation's history.
What distinguishes Salt Typhoon from most espionage-motivated APT activity is the specific nature of the access it sought: rather than stealing intellectual property or financial data, the group targeted telecom carriers' "lawful intercept" systems — the infrastructure that facilitates court-authorized wiretaps — along with call detail records and customer geolocation data. The FBI confirmed the group accessed communications and metadata belonging to a limited number of predominantly government and political figures, including individuals then associated with the 2024 U.S. presidential campaigns, and copied information about which numbers U.S. law enforcement was actively surveilling.
Salt Typhoon's scale is exceptional even by nation-state standards: FBI and CISA assessments place its confirmed or suspected footprint at more than 80 countries and roughly 600 notified organizations, spanning telecommunications, government, transportation, lodging, and military sectors. Unlike many Chinese APT clusters that operate as uniformed military units, Salt Typhoon's operations have been traced to at least three ostensibly private Chinese technology companies — Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology, and Sichuan Zhixin Ruijie Network Technology — that the U.S. Treasury Department assesses function as contractors providing cyber capabilities directly to Chinese intelligence services, a "state-corporate" operating model increasingly common among Chinese APT groups.
The group remains fully active as of 2026 despite sustained pressure: an August 2025 joint CISA/NSA/FBI advisory, September 2025 Treasury sanctions against Sichuan Juxinhe, and continued congressional oversight have not visibly reduced its operational tempo. New intrusions — including a suspected compromise of U.S. House committee staff email systems handling China policy, foreign affairs, and intelligence oversight, and confirmed compromises in Norway disclosed in that country's 2026 threat assessment — indicate the group continues both to expand geographically and to escalate the sensitivity of its targeting.
HIGH on state sponsorship. US government agencies (FBI, CISA, NSA, Treasury/OFAC) and multiple independent vendors (Microsoft, Trend Micro, Kaspersky, ESET, Mandiant, Recorded Future) converge on attributing this activity cluster to Chinese state sponsorship via the Ministry of State Security, corroborated by Treasury's formal sanctions designation of a specific contractor company. Confidence in the precise institutional chain is MEDIUM — which MSS bureau directly taskes the contractor companies, and how cleanly "Salt Typhoon" separates from adjacent clusters like GhostEmperor/Earth Estries at the level of individual personnel, remains an open question reflecting the loosely federated, contractor-based structure increasingly typical of Chinese cyber operations. Note: separate March 2025 DOJ indictments of individuals named "Yin Kecheng" and "Zhou Shuai" concern APT27-linked hacking-for-hire activity; public reporting has not conclusively resolved whether this is the same Yin Kecheng sanctioned for the Salt Typhoon/Treasury intrusion — an acknowledged gap in this profile rather than a confirmed link.
Salt Typhoon's initial access is dominated by exploitation of known, often long-unpatched vulnerabilities in internet-facing network edge devices rather than novel zero-days or social engineering. The group has weaponized a seven-year-old flaw in Cisco's IOS Smart Install feature (CVE-2018-0171) and chained a 2023 Cisco IOS XE web-UI privilege-escalation bug with a companion root-access flaw (CVE-2023-20198/CVE-2023-20273) to compromise carrier-grade routers and switches directly, alongside documented exploitation of vulnerabilities in Ivanti Connect Secure VPN, Fortinet FortiClient EMS, Sophos firewalls, and Microsoft Exchange in adjacent Earth Estries campaigns.
Once on a device, the group favors "living off the land" on network infrastructure itself rather than deploying conventional endpoint malware: dumping device configuration files to harvest weakly encrypted stored credentials, brute-forcing what it recovers, adding SSH authorized_keys entries and creating new Linux-level accounts directly in /etc/shadow and /etc/passwd for durable, credential-independent persistence, and altering Access Control Lists and loopback interface addresses to bypass network segmentation controls. Where custom tooling is deployed, it is purpose-built for the carrier environment — the JumbledPath utility handles archiving, log-clearing, infrastructure hiding, and multi-stage covert communications, while modular backdoors like GhostSpider, the Demodex rootkit, and the shared Chinese-APT tool SnappyBee provide flexible, victim-tailored capability.
The group's ultimate objective — access to lawful-intercept and call-detail infrastructure — is achieved through direct network sniffing between compromised device interfaces and the establishment of covert GRE tunnels that let operators pivot deep into carrier backbones while evading conventional network monitoring. Exfiltration of harvested configuration data typically leaves the network over unencrypted FTP/TFTP sessions rather than a distinct C2 channel, blending with legitimate device-management traffic and complicating detection in environments where network device logging and monitoring are historically underinvested compared to endpoint security.
| Type | Value / Description | Source | Date |
|---|---|---|---|
| CVE | CVE-2018-0171 — Cisco IOS Smart Install remote code execution | Cisco Talos / CISA | Disclosed 2018; exploited 2024–2025 |
| CVE | CVE-2023-20198 — Cisco IOS XE Web UI privilege escalation (initial access) | Cisco / CISA KEV | Disclosed 2023-10; exploited Dec 2024–Jan 2025 |
| CVE | CVE-2023-20273 — Cisco IOS XE root-access flaw (chained with above) | Cisco / CISA KEV | Disclosed 2023-10; exploited Dec 2024–Jan 2025 |
| MALWARE | JumbledPath, GhostSpider, Demodex, SnappyBee, Masol RAT | Trend Micro; Recorded Future; CISA/NSA/FBI joint advisory | 2024–2025 |
| SANCTIONED ENTITY | Sichuan Juxinhe Network Technology Co., Ltd. | US Treasury / OFAC | 2025-09 |
| NOTE | No durable static IP/domain indicator list is included here. Salt Typhoon compromises carrier-owned network devices directly, and its infrastructure (compromised routers, hop points) is victim-specific and rotates constantly. Consult the August 2025 CISA/NSA/FBI joint advisory and named vendor reporting (Recorded Future "RedMike," Trend Micro "Earth Estries") for current, environment-specific indicators rather than a static list reproduced here. | ||
Salt Typhoon represents a doctrinal shift that should concern defenders beyond the telecom sector specifically: rather than treating network infrastructure devices as plumbing to be patched opportunistically, this group treats routers, VPN concentrators, and firewalls as the primary target — the place where durable, high-value access lives — and has demonstrated it can operate there for extended periods with minimal reliance on conventional, more heavily monitored endpoint malware. Its specific interest in lawful-intercept systems is a notable escalation: it targets not just communications but the infrastructure meant to safeguard those communications' legal-authorization boundaries, giving a foreign intelligence service potential visibility into who US law enforcement is investigating.
The group's contractor-based operating model — MSS tasking ostensibly private companies like Sichuan Juxinhe rather than uniformed military units — mirrors a broader trend across Chinese state-sponsored activity and complicates both attribution and disruption: sanctioning or even successfully prosecuting one contractor company does not necessarily remove the underlying MSS tasking relationship or the pool of technical talent available to service it. This helps explain why sustained diplomatic and legal pressure through 2025 has not visibly reduced Salt Typhoon's operational tempo into 2026.
Confidence in this assessment would increase with independently verified confirmation that named US carriers have fully evicted the group — currently a contested claim given Senate inquiries into withheld third-party forensic reports — and would improve if the September 2025 sanctions or a future criminal indictment meaningfully disrupted the specific contractor relationships enabling the group's edge-device tooling pipeline. The clearest forward risk is further escalation up the sensitivity ladder: having already reached telecom wiretap systems, a federal agency network (Treasury), and now congressional committee staff email, further targeting of comparably sensitive US government functions should be treated as a realistic near-term possibility rather than a worst-case outlier.