{"id":502,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2019<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">China (MSS)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage, Telecommunications Intelligence<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Telecommunications network infiltration, wiretapping law enforcement intercept systems, metadata collection<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">GhostEmperor, FamousSparrow, Earth Estries<\/div>\n  <\/div>\n<\/div>\n<p>Salt Typhoon is a Chinese state-sponsored advanced persistent threat group that gained significant international attention in 2024 following the revelation of a sweeping, years-long espionage campaign targeting major US telecommunications providers including AT&amp;T, Verizon, and Lumen Technologies. The scale and audacity of the intrusions led the US Senate Intelligence Committee to describe it as \"the worst telecom hack in our nation's history.\"<\/p>\n<p>The group's primary objective in the telecommunications campaign was to access the lawful intercept systems ,  the infrastructure that US carriers maintain to comply with court-ordered wiretapping requests under the Communications Assistance for Law Enforcement Act (CALEA). By compromising these systems, Salt Typhoon potentially gained access to communications of Chinese intelligence targets already under US law enforcement surveillance, providing Beijing with extraordinary counterintelligence insight into ongoing US investigations of Chinese espionage operations.<\/p>\n<p>Beyond the US telecommunications campaign, Salt Typhoon has conducted long-running espionage operations against government and private sector targets in Southeast Asia, the Middle East, and Africa, demonstrating a broad geographic mandate. The group has been active since at least 2019, with evidence suggesting even earlier preliminary reconnaissance activity.<\/p>\n<p>Salt Typhoon uses a sophisticated custom malware ecosystem including the GhostSpider backdoor and MASOL RAT, alongside aggressive exploitation of vulnerabilities in network edge devices. The telecommunications campaign has prompted emergency FCC regulatory action and intensified debates within the US government about the security of critical communications infrastructure.<\/p>\n\n<p><strong>Cyber Espionage Tactics and Persistence Mechanisms:<\/strong> Operational tracking indicates that <strong>Salt Typhoon<\/strong> executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.<\/p>","link":"https:\/\/cyberasia.io\/actor\/salt-typhoon\/","name":"Salt Typhoon","slug":"salt-typhoon","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/502","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}