Rook ReportsOpen-Source
Intelligence
Sign in
Dossier · Threat Group

Salt Typhoon

Last assessed 16 JUN 2026Confidence ModerateSources A2–C3Referenced in 1 report

Salt Typhoon is a People's Republic of China-attributed cyber-espionage cluster that, in late 2024, US agencies and major outlets disclosed had compromised multiple US telecommunications providers and lawful-intercept systems across an extended access period [1·A2] [2·B2]. It is tracked under several aliases, Earth Estries, FamousSparrow, GhostEmperor, UNC2286, with overlapping but not identical footprints [3·B2].

Background

Public activity attributed to the cluster now tracked as Salt Typhoon dates to approximately 2019, with predecessor footprints visible in earlier vendor reporting under different aliases [3·B2]. Across the following five-plus years, the group has targeted telecommunications operators, government bodies, and technology infrastructure across multiple regions.

The September–October 2024 public disclosures by CISA, the FBI, the NSA, and major outlets brought the cluster to broad public attention, attributing intrusions affecting multiple US telecommunications providers and lawful-intercept systems [1·A2] [2·B2].

Attribution

Joint US government statements characterized the responsible actor as affiliated with the People's Republic of China [1·A2]. Private-sector research from multiple firms independently identified the cluster as PRC-linked, several associating activity with Ministry of State Security sponsorship based on tooling, targeting, and tradecraft consistency [6·B3] [7·B2].

It is assessed as almost certainly the case that the cluster operates with PRC state direction, and as likely the case that the operating service is the MSS rather than an alternative service. The lower confidence on the specific service reflects the absence of confirmation in published joint advisories at the time of assessment.

Tactics, techniques & procedures

Long-dwell-time intrusions rely on living-off-the-land techniques and legitimate admin tooling rather than novel implants. Photo: drop credit here

Documented TTPs cluster around three patterns: exploitation of network-edge devices (routers and infrastructure equipment), living-off-the-land lateral movement using legitimate administrative tooling, and extended dwell times measured in months [4·B2].

Tools & malware

Associated tooling includes the GhostEmperor / Demodex kernel-mode rootkit family and the SparrowDoor backdoor used in FamousSparrow operations [3·B2] [8·B2]. Vendor naming reflects independent discovery rather than distinct operations.

Notable incidents

The 2024 US telecommunications intrusions affected multiple providers and reportedly touched lawful-intercept infrastructure, prompting joint federal advisories and sustained newsroom investigation [1·A2] [2·B2].

Targeting profile

Target selection has focused on telecommunications operators, government entities, and adjacent technology infrastructure across the United States, Southeast Asia, Latin America, and parts of Europe [4·B2] [5·C3].

Relationship graph

Entities, aliases, tooling, and victims as resolved on the Corvus Codex. Hover to isolate links, drag to explore, ⌘/Ctrl-scroll to zoom.

Salt TyphoonEarth EstriesFamousSparrowGhostEmperorUNC2286Demodex rootkitSparrowDoorUS TelecomGovernmentPRC · MSS

Defensive guidance

Prioritize edge-device patching and configuration audit, monitor for anomalous administrative tooling on network infrastructure, and constrain dwell time through segmentation and credential hygiene. Cross-reference MITRE ATT&CK technique coverage against observed TTPs.

R# analysis

On current evidence, attribution to the PRC is almost certainly correct; MSS sponsorship is likely but not confirmed in joint advisories. The cluster's reliance on edge-device exploitation and living-off-the-land tradecraft makes detection a function of infrastructure visibility rather than implant signatures, defenders with weak edge telemetry are structurally disadvantaged.

Evidence register

  1. A21CISA, FBI, NSA. Joint advisory on PRC-attributed compromises of US telecommunications infrastructure. Late 2024. cisa.gov.
  2. B22Reporting on Salt Typhoon US telecom intrusions across major outlets, late 2024. NYT, WSJ, Washington Post, corroborated across independent investigations.
  3. B23Kaspersky Lab. GhostEmperor: rootkit and tooling analysis. Vendor research, 2021 onward.
  4. B24Trend Micro. Earth Estries activity analysis: TTPs, tooling, targeting. Vendor research, 2023–2024.
  5. C35Regional intrusion reports across European and Latin American jurisdictions. Mixed-source; not all independently corroborated.
  6. B36Vendor and analyst characterizations of MSS sponsorship. Sponsorship-specific attribution not confirmed in joint advisories at time of assessment.
  7. B27Mandiant. UNC2286 tracking and overlap analysis. Vendor research, ongoing.
  8. B28ESET. FamousSparrow tracking: SparrowDoor backdoor and operations. Vendor research, 2021 onward.
Classification
Threat groupState-sponsoredPRCEspionageTelecommunicationsEdge-device exploitationActive
Graded on NATO Admiralty source qualification (STANAG 2511) · Berkeley-Protocol chain of custody · ICD 203 estimative language · Not legal advice.