Skip to content
ChinaState-SponsoredActive

Salt Typhoon

Compromised the core of U.S. telecommunications — including the lawful intercept systems used for court-ordered wiretaps.

Download profile JSON
Active
2019–present
Motivation
Espionage
Aliases
8
Exploited CVEs
6
ATT&CK techniques
11
Cited sources
13

Overview

Salt Typhoon executed what U.S. officials have described as the most significant telecommunications breach in the nation's history.

Between 2022 and 2024 the group established deep access inside at least nine U.S. telecommunications providers — reporting has named AT&T, Verizon, Lumen, T-Mobile, and Charter among them — plus dozens of operators worldwide. Rather than breaching handsets or applications, it compromised the carriers themselves: core routers, provisioning systems, and call detail record infrastructure.

The most consequential access was to lawful intercept systems — the CALEA-mandated infrastructure U.S. carriers maintain to service court-ordered wiretaps. Compromising it gave the actor visibility into which individuals U.S. law enforcement and counterintelligence were actively monitoring, a counterintelligence coup independent of any content collected. The group also accessed communications of individuals involved in the 2024 U.S. presidential campaigns and obtained call metadata for large numbers of subscribers, concentrated in the Washington, D.C. area.

Tradecraft centres on network infrastructure rather than endpoints. The group lives on routers and switches, where EDR does not run, telemetry is sparse, and defenders rarely look. It uses stolen credentials, modifies device configurations to create durable access, and in several cases exploited network devices that had been unpatched for years — CVE-2018-0171, a Cisco Smart Install flaw patched in 2018, was still an effective entry point in 2024.

In August 2025 a joint advisory from thirteen countries named three Chinese companies — Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology, and Sichuan Zhixin Ruijie Network Technology — as providers of cyber products and services to Chinese intelligence services in support of this activity.

Attribution

Down to the named unit where public evidence supports it.

ChinaMinistry of State Security (MSS), via contractor front companiesHigh confidence

Attributed to PRC state-sponsored actors by CISA, NSA, and FBI. The U.S. Treasury sanctioned Sichuan Juxinhe Network Technology in January 2025, stating it had direct involvement in the Salt Typhoon compromises and maintains close ties to the MSS. An August 2025 advisory co-sealed by thirteen countries named three PRC-based companies supplying cyber products and services to Chinese intelligence services in support of the campaign.

Attributing sources

Cross-vendor naming crosswalk

8 designators across 8 organisations.

2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

Microsoft Threat Intelligence

index ↗
  • Salt Typhoon

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • OPERATOR PANDA

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • UNC5807

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • BRONZE ESSAYpartialPartial overlap with the tracked activity set

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Recorded Future Insikt Group

index ↗
  • RedMike

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Kaspersky GReAT

index ↗
  • GhostEmperorpartialKaspersky's 2021 cluster centred on the Demodex rootkit; assessed as overlapping

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Trend Micro

index ↗
  • Earth Estries

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

CISA / NSA / FBI

index ↗
  • Salt Typhoon

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesCanadaUnited KingdomAustraliaGermanyItalySouth AfricaTaiwanThailand

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Demodexmalware

Kernel-mode rootkit loaded via a signed vulnerable driver, concealing processes and network connections on compromised servers.

GhostSpiderbackdoor

Modular multi-stage backdoor loading components in memory only, used against telecommunications infrastructure.

SNAPPYBEEbackdoor

Modular implant shared across several Chinese state-nexus groups, complicating cluster boundaries.

JumbledPathutility

Go-based utility for capturing packets on remote Cisco devices via a jump-host chain, with automated log clearing.

Masol RATbackdoor

Linux implant observed on Southeast Asian government targets.

Shared, commodity & living-off-the-land

Cisco IOS configuration abuselotl

GRE tunnels, modified ACLs, and added local accounts on core routers for persistent, protocol-native access.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Salt Typhoon
CVE-2023-46805KEVransomware8.21 Feb 2024Ivanti Connect Secure authentication bypass chained with CVE-2024-21887 for access to targeted networks.SRCNSA / CISA / FBI and international partners
CVE-2024-21887KEVransomware9.11 Feb 2024Ivanti command injection used for remote code execution on VPN appliances at telecommunications providers.SRCNSA / CISA / FBI and international partners
CVE-2018-0171KEV9.81 Jan 2024Cisco Smart Install remote code execution — patched in 2018 — still yielding access to unpatched edge routers six years later. A pointed illustration that network devices fall outside most patch programmes.SRCNSA / CISA / FBI and international partners
CVE-2023-20198KEV10.01 Oct 2023Cisco IOS XE web UI privilege escalation used to create level-15 accounts on carrier and enterprise routers, then configure GRE tunnels for persistent traffic interception.SRCRecorded Future Insikt Group
CVE-2022-1388KEVransomware9.81 Jun 2022F5 BIG-IP iControl REST authentication bypass used for perimeter access and lateral movement.SRCTrend Micro
CVE-2021-26855KEVransomware9.81 Aug 2021ProxyLogon exploitation of Exchange servers at government and telecommunications targets in Southeast Asia.SRCTrend Micro

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

5 stages · 11 techniques
  1. 01

    Initial Access

    2 techniques

    Network devices, frequently ones unpatched for years. CVE-2018-0171 — a Cisco Smart Install flaw fixed in 2018 — was still yielding access to carrier edge routers in 2024, because network equipment sits outside most organisations' patch programmes entirely.

  2. 04

    Collection

    1 technique

    Bulk call detail records and metadata, the communications of specific individuals under U.S. political and government scrutiny, and — most consequentially — the CALEA lawful intercept systems, which reveal who U.S. law enforcement was itself monitoring.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

11 techniques across 5 tactics · 9 with actor-specific notes

Initial Access

2

Credential Access

2

Collection

1

Command and Control

2

Campaign timeline

  1. landmark

    U.S. Telecommunications Compromise

    Deep access to at least nine U.S. telecommunications providers, including the CALEA lawful intercept systems used for court-ordered wiretaps — revealing which individuals U.S. law enforcement was actively monitoring. Communications of individuals involved in the 2024 presidential campaigns were accessed, alongside bulk call metadata.

    CVE-2023-20198CVE-2018-0171TelecommunicationsGovernmentPolitical Organizations

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.