{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "salt-typhoon",
    "slug": "salt-typhoon",
    "name": "Salt Typhoon",
    "shortName": "Salt Typhoon",
    "country": "China",
    "countryCode": "CN",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2019",
    "prominence": 94,
    "tagline": "Compromised the core of U.S. telecommunications — including the lawful intercept systems used for court-ordered wiretaps.",
    "bio": "Salt Typhoon executed what U.S. officials have described as the most significant telecommunications breach in the nation's history.\n\nBetween 2022 and 2024 the group established deep access inside at least nine U.S. telecommunications providers — reporting has named AT&T, Verizon, Lumen, T-Mobile, and Charter among them — plus dozens of operators worldwide. Rather than breaching handsets or applications, it compromised the carriers themselves: core routers, provisioning systems, and call detail record infrastructure.\n\nThe most consequential access was to lawful intercept systems — the CALEA-mandated infrastructure U.S. carriers maintain to service court-ordered wiretaps. Compromising it gave the actor visibility into which individuals U.S. law enforcement and counterintelligence were actively monitoring, a counterintelligence coup independent of any content collected. The group also accessed communications of individuals involved in the 2024 U.S. presidential campaigns and obtained call metadata for large numbers of subscribers, concentrated in the Washington, D.C. area.\n\nTradecraft centres on network infrastructure rather than endpoints. The group lives on routers and switches, where EDR does not run, telemetry is sparse, and defenders rarely look. It uses stolen credentials, modifies device configurations to create durable access, and in several cases exploited network devices that had been unpatched for years — CVE-2018-0171, a Cisco Smart Install flaw patched in 2018, was still an effective entry point in 2024.\n\nIn August 2025 a joint advisory from thirteen countries named three Chinese companies — Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology, and Sichuan Zhixin Ruijie Network Technology — as providers of cyber products and services to Chinese intelligence services in support of this activity.",
    "attribution": {
      "sponsor": "China",
      "service": "Ministry of State Security (MSS), via contractor front companies",
      "confidence": "high",
      "summary": "Attributed to PRC state-sponsored actors by CISA, NSA, and FBI. The U.S. Treasury sanctioned Sichuan Juxinhe Network Technology in January 2025, stating it had direct involvement in the Salt Typhoon compromises and maintains close ties to the MSS. An August 2025 advisory co-sealed by thirteen countries named three PRC-based companies supplying cyber products and services to Chinese intelligence services in support of the campaign.",
      "sources": [
        {
          "org": "U.S. Department of the Treasury",
          "title": "Treasury Sanctions Technology Company for Support to Salt Typhoon Malicious Cyber Group",
          "url": "https://home.treasury.gov/news/press-releases/jy2792",
          "date": "2025-01-17"
        },
        {
          "org": "NSA / CISA / FBI and international partners",
          "title": "Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide (AA25-239A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a",
          "date": "2025-08-27"
        },
        {
          "org": "CISA / FBI",
          "title": "Joint Statement on PRC Targeting of Commercial Telecommunications Infrastructure",
          "url": "https://www.cisa.gov/news-events/news/joint-statement-fbi-and-cisa-peoples-republic-china-prc-targeting-commercial-telecommunications",
          "date": "2024-10-25"
        }
      ]
    },
    "motivations": [
      "espionage"
    ],
    "targetSectors": [
      "Telecommunications",
      "Government",
      "Critical Infrastructure",
      "Technology",
      "Political Organizations",
      "Defense",
      "Transportation"
    ],
    "targetCountries": [
      "United States",
      "Canada",
      "United Kingdom",
      "Australia",
      "Germany",
      "Italy",
      "South Africa",
      "Taiwan",
      "Thailand"
    ],
    "aliases": [
      {
        "org": "microsoft",
        "name": "Salt Typhoon",
        "correlation": "exact"
      },
      {
        "org": "crowdstrike",
        "name": "OPERATOR PANDA",
        "correlation": "exact"
      },
      {
        "org": "trendmicro",
        "name": "Earth Estries",
        "correlation": "exact"
      },
      {
        "org": "kaspersky",
        "name": "GhostEmperor",
        "correlation": "partial",
        "note": "Kaspersky's 2021 cluster centred on the Demodex rootkit; assessed as overlapping"
      },
      {
        "org": "recordedfuture",
        "name": "RedMike",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "UNC5807",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "Salt Typhoon",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "BRONZE ESSAY",
        "correlation": "partial",
        "note": "Partial overlap with the tracked activity set"
      }
    ],
    "tools": [
      {
        "name": "Demodex",
        "type": "malware",
        "custom": true,
        "description": "Kernel-mode rootkit loaded via a signed vulnerable driver, concealing processes and network connections on compromised servers."
      },
      {
        "name": "GhostSpider",
        "type": "backdoor",
        "custom": true,
        "description": "Modular multi-stage backdoor loading components in memory only, used against telecommunications infrastructure."
      },
      {
        "name": "SNAPPYBEE",
        "type": "backdoor",
        "custom": true,
        "description": "Modular implant shared across several Chinese state-nexus groups, complicating cluster boundaries."
      },
      {
        "name": "JumbledPath",
        "type": "utility",
        "custom": true,
        "description": "Go-based utility for capturing packets on remote Cisco devices via a jump-host chain, with automated log clearing."
      },
      {
        "name": "Cisco IOS configuration abuse",
        "type": "lotl",
        "custom": false,
        "description": "GRE tunnels, modified ACLs, and added local accounts on core routers for persistent, protocol-native access."
      },
      {
        "name": "Masol RAT",
        "type": "backdoor",
        "custom": true,
        "description": "Linux implant observed on Southeast Asian government targets."
      }
    ],
    "techniques": [
      {
        "tCode": "T1190",
        "name": "Exploit Public-Facing Application",
        "tactic": "Initial Access",
        "note": "Cisco IOS XE, Ivanti, Fortinet, and Exchange appliances"
      },
      {
        "tCode": "T1078",
        "name": "Valid Accounts",
        "tactic": "Initial Access",
        "note": "Stolen credentials, including from third-party providers and vendors"
      },
      {
        "tCode": "T1601.001",
        "name": "Modify System Image: Patch System Image",
        "tactic": "Defense Evasion",
        "note": "Modification of network device firmware and running configuration"
      },
      {
        "tCode": "T1599.001",
        "name": "Network Boundary Bridging: Network Address Translation Traversal",
        "tactic": "Defense Evasion"
      },
      {
        "tCode": "T1572",
        "name": "Protocol Tunneling",
        "tactic": "Command and Control",
        "note": "GRE and IPsec tunnels created on core routers"
      },
      {
        "tCode": "T1040",
        "name": "Network Sniffing",
        "tactic": "Credential Access",
        "note": "Packet capture on carrier infrastructure via JumbledPath"
      },
      {
        "tCode": "T1014",
        "name": "Rootkit",
        "tactic": "Defense Evasion",
        "note": "Demodex kernel driver"
      },
      {
        "tCode": "T1070.001",
        "name": "Indicator Removal: Clear Windows Event Logs",
        "tactic": "Defense Evasion",
        "note": "Automated log clearing on network devices after each session"
      },
      {
        "tCode": "T1556",
        "name": "Modify Authentication Process",
        "tactic": "Credential Access"
      },
      {
        "tCode": "T1119",
        "name": "Automated Collection",
        "tactic": "Collection",
        "note": "Bulk call detail record and metadata extraction"
      },
      {
        "tCode": "T1090.003",
        "name": "Proxy: Multi-hop Proxy",
        "tactic": "Command and Control",
        "note": "Chained compromised devices to obscure origin"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2023-20198",
        "firstExploited": "2023-10-01",
        "usage": "Cisco IOS XE web UI privilege escalation used to create level-15 accounts on carrier and enterprise routers, then configure GRE tunnels for persistent traffic interception.",
        "source": {
          "org": "Recorded Future Insikt Group",
          "title": "RedMike (Salt Typhoon) Exploits Cisco Devices at Telecommunications Providers",
          "url": "https://www.recordedfuture.com/research/redmike-salt-typhoon-exploits-vulnerable-devices",
          "date": "2025-02-13"
        }
      },
      {
        "cveId": "CVE-2018-0171",
        "firstExploited": "2024-01-01",
        "usage": "Cisco Smart Install remote code execution — patched in 2018 — still yielding access to unpatched edge routers six years later. A pointed illustration that network devices fall outside most patch programmes.",
        "source": {
          "org": "NSA / CISA / FBI and international partners",
          "title": "Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide (AA25-239A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a",
          "date": "2025-08-27"
        }
      },
      {
        "cveId": "CVE-2023-46805",
        "firstExploited": "2024-02-01",
        "usage": "Ivanti Connect Secure authentication bypass chained with CVE-2024-21887 for access to targeted networks.",
        "source": {
          "org": "NSA / CISA / FBI and international partners",
          "title": "Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide (AA25-239A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a",
          "date": "2025-08-27"
        }
      },
      {
        "cveId": "CVE-2024-21887",
        "firstExploited": "2024-02-01",
        "usage": "Ivanti command injection used for remote code execution on VPN appliances at telecommunications providers.",
        "source": {
          "org": "NSA / CISA / FBI and international partners",
          "title": "Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide (AA25-239A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a",
          "date": "2025-08-27"
        }
      },
      {
        "cveId": "CVE-2021-26855",
        "firstExploited": "2021-08-01",
        "usage": "ProxyLogon exploitation of Exchange servers at government and telecommunications targets in Southeast Asia.",
        "source": {
          "org": "Trend Micro",
          "title": "Earth Estries Targets Government and Tech Sectors",
          "url": "https://www.trendmicro.com/en_us/research/23/h/earth-estries-targets-government-tech-for-cyberespionage.html",
          "date": "2023-08-30"
        }
      },
      {
        "cveId": "CVE-2022-1388",
        "firstExploited": "2022-06-01",
        "usage": "F5 BIG-IP iControl REST authentication bypass used for perimeter access and lateral movement.",
        "source": {
          "org": "Trend Micro",
          "title": "Earth Estries Targets Government and Tech Sectors",
          "url": "https://www.trendmicro.com/en_us/research/23/h/earth-estries-targets-government-tech-for-cyberespionage.html",
          "date": "2023-08-30"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "volt-typhoon",
        "type": "same-sponsor",
        "confidence": "high",
        "note": "Both PRC state-sponsored against telecommunications, with opposite objectives: Salt Typhoon collects, Volt Typhoon pre-positions."
      },
      {
        "relatedActorId": "apt41",
        "type": "shared-tooling",
        "confidence": "moderate",
        "note": "SNAPPYBEE and related implants appear across multiple Chinese state-nexus clusters, consistent with a shared contractor supply chain."
      },
      {
        "relatedActorId": "silk-typhoon",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both MSS-linked with a shared pattern of exploiting trusted upstream providers to reach many downstream victims."
      }
    ],
    "reports": [
      {
        "org": "Trend Micro",
        "title": "Earth Estries: A Closer Look at the Sophisticated Cyberespionage Toolset",
        "url": "https://www.trendmicro.com/en_us/research/24/k/earth-estries.html",
        "date": "2024-11-25"
      },
      {
        "org": "CISA / NSA / FBI and partners",
        "title": "AA25-239A: Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide",
        "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a",
        "date": "2025-08-27"
      },
      {
        "org": "Recorded Future Insikt Group",
        "title": "RedMike Exploits Unpatched Cisco Devices to Target Telecommunications Providers",
        "url": "https://www.recordedfuture.com/research/redmike-salt-typhoon-exploits-vulnerable-devices",
        "date": "2025-02-13"
      },
      {
        "org": "Cisco Talos",
        "title": "Salt Typhoon: Weathering the storm in the telecom sector",
        "url": "https://blog.talosintelligence.com/salt-typhoon-analysis/",
        "date": "2025-02-20"
      }
    ],
    "campaigns": [
      {
        "id": "salt-telecom",
        "actorId": "salt-typhoon",
        "name": "U.S. Telecommunications Compromise",
        "date": "2022-01-01",
        "endDate": "2024-12-01",
        "significance": "landmark",
        "targetSectors": [
          "Telecommunications",
          "Government",
          "Political Organizations"
        ],
        "targetCountries": [
          "United States",
          "Canada",
          "United Kingdom",
          "Australia"
        ],
        "cveIds": [
          "CVE-2023-20198",
          "CVE-2018-0171"
        ],
        "summary": "Deep access to at least nine U.S. telecommunications providers, including the CALEA lawful intercept systems used for court-ordered wiretaps — revealing which individuals U.S. law enforcement was actively monitoring. Communications of individuals involved in the 2024 presidential campaigns were accessed, alongside bulk call metadata.",
        "sources": [
          {
            "org": "CISA / FBI",
            "title": "Joint Statement on PRC Targeting of Commercial Telecommunications Infrastructure",
            "url": "https://www.cisa.gov/news-events/news/joint-statement-fbi-and-cisa-peoples-republic-china-prc-targeting-commercial-telecommunications",
            "date": "2024-10-25"
          },
          {
            "org": "NSA / CISA and 13 international partners",
            "title": "AA25-239A: Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide",
            "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a",
            "date": "2025-08-27"
          }
        ]
      }
    ],
    "flag": "🇨🇳",
    "profile": "/apt/salt-typhoon/"
  }
}