🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
SALT TYPHOON

/actor/salt-typhoon/  ·  0 intel reports

Year Established
2019
Attribution
China (MSS)
Motivation
Espionage, Telecommunications Intelligence
Modus Operandi (MO)
Telecommunications network infiltration, wiretapping law enforcement intercept systems, metadata collection
Primary Aliases
GhostEmperor, FamousSparrow, Earth Estries

Salt Typhoon is a Chinese state-sponsored advanced persistent threat group that gained significant international attention in 2024 following the revelation of a sweeping, years-long espionage campaign targeting major US telecommunications providers including AT&T, Verizon, and Lumen Technologies. The scale and audacity of the intrusions led the US Senate Intelligence Committee to describe it as "the worst telecom hack in our nation's history."

The group's primary objective in the telecommunications campaign was to access the lawful intercept systems , the infrastructure that US carriers maintain to comply with court-ordered wiretapping requests under the Communications Assistance for Law Enforcement Act (CALEA). By compromising these systems, Salt Typhoon potentially gained access to communications of Chinese intelligence targets already under US law enforcement surveillance, providing Beijing with extraordinary counterintelligence insight into ongoing US investigations of Chinese espionage operations.

Beyond the US telecommunications campaign, Salt Typhoon has conducted long-running espionage operations against government and private sector targets in Southeast Asia, the Middle East, and Africa, demonstrating a broad geographic mandate. The group has been active since at least 2019, with evidence suggesting even earlier preliminary reconnaissance activity.

Salt Typhoon uses a sophisticated custom malware ecosystem including the GhostSpider backdoor and MASOL RAT, alongside aggressive exploitation of vulnerabilities in network edge devices. The telecommunications campaign has prompted emergency FCC regulatory action and intensified debates within the US government about the security of critical communications infrastructure.

Cyber Espionage Tactics and Persistence Mechanisms: Operational tracking indicates that Salt Typhoon executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles