NEW: Group Profiler — instant APT intel lookup. Try it →

Salt Typhoon

G1045 China MITRE ATT&CK →

Overview

Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).

Naming & attribution

Salt Typhoon is tracked under 1 names across the industry. It uses 14 documented ATT&CK techniques — more than 40% of the 174 groups tracked here. Activity attributed since at least 2019.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1602.002 Network Device Configuration Dump — used by 1 of 174 groups
  • T1098.004 SSH Authorized Keys — used by 3 of 174 groups
  • T1136 Create Account — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Moses Staff Iran — 3 shared techniques (13% overlap)
  • BlackTech China — 3 shared techniques (12% overlap)
  • FIN13 — 6 shared techniques (10% overlap)
  • Cinnamon Tempest China — 3 shared techniques (10% overlap)
  • UNC3886 China — 5 shared techniques (9% overlap)
  • Rocke China — 4 shared techniques (9% overlap)

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190

TTPs — 14 techniques across 10 tactics

Reconnaissance

Resource Development

Initial Access

Persistence

Credential Access

Lateral Movement

  • T1021.004 SSH

Collection

Command and Control

Tools & malware (1)

JumbledPath

Reporting (2)