Salt Typhoon
Overview
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).
Naming & attribution
Salt Typhoon is tracked under 1 names across the industry. It uses 14 documented ATT&CK techniques — more than 40% of the 174 groups tracked here. Activity attributed since at least 2019.
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1602.002Network Device Configuration Dump — used by 1 of 174 groups -
T1098.004SSH Authorized Keys — used by 3 of 174 groups -
T1136Create Account — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Moses Staff Iran — 3 shared techniques (13% overlap)
- BlackTech China — 3 shared techniques (12% overlap)
- FIN13 — 6 shared techniques (10% overlap)
- Cinnamon Tempest China — 3 shared techniques (10% overlap)
- UNC3886 China — 5 shared techniques (9% overlap)
- Rocke China — 4 shared techniques (9% overlap)
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
TTPs — 14 techniques across 10 tactics
Reconnaissance
-
T1590.004Network Topology
Initial Access
Persistence
-
T1098.004SSH Authorized Keys -
T1136Create Account
Defense Impairment
-
T1685.006Clear Linux or Mac System Logs -
T1686Disable or Modify System Firewall
Credential Access
-
T1040Network Sniffing -
T1110.002Password Cracking
Lateral Movement
-
T1021.004SSH
Collection
-
T1602.002Network Device Configuration Dump
Command and Control
-
T1572Protocol Tunneling
Exfiltration
Tools & malware (1)
JumbledPath
Reporting (2)
- Weathering the storm: In the midst of a Typhoon — Cisco Talos
- Treasury Sanctions Company Associated with Salt Typhoon and Hacker Associated with Treasury Compromise — US Department of Treasury