Salt Typhoon
Salt Typhoon is a People's Republic of China-attributed cyber-espionage cluster that, in late 2024, US agencies and major outlets disclosed had compromised multiple US telecommunications providers and lawful-intercept systems across an extended access period [1·A2] [2·B2]. It is tracked under several aliases, Earth Estries, FamousSparrow, GhostEmperor, UNC2286, with overlapping but not identical footprints [3·B2].
Background
Public activity attributed to the cluster now tracked as Salt Typhoon dates to approximately 2019, with predecessor footprints visible in earlier vendor reporting under different aliases [3·B2]. Across the following five-plus years, the group has targeted telecommunications operators, government bodies, and technology infrastructure across multiple regions.
The September–October 2024 public disclosures by CISA, the FBI, the NSA, and major outlets brought the cluster to broad public attention, attributing intrusions affecting multiple US telecommunications providers and lawful-intercept systems [1·A2] [2·B2].
Attribution
Joint US government statements characterized the responsible actor as affiliated with the People's Republic of China [1·A2]. Private-sector research from multiple firms independently identified the cluster as PRC-linked, several associating activity with Ministry of State Security sponsorship based on tooling, targeting, and tradecraft consistency [6·B3] [7·B2].
It is assessed as almost certainly the case that the cluster operates with PRC state direction, and as likely the case that the operating service is the MSS rather than an alternative service. The lower confidence on the specific service reflects the absence of confirmation in published joint advisories at the time of assessment.
Tactics, techniques & procedures
Documented TTPs cluster around three patterns: exploitation of network-edge devices (routers and infrastructure equipment), living-off-the-land lateral movement using legitimate administrative tooling, and extended dwell times measured in months [4·B2].
Tools & malware
Associated tooling includes the GhostEmperor / Demodex kernel-mode rootkit family and the SparrowDoor backdoor used in FamousSparrow operations [3·B2] [8·B2]. Vendor naming reflects independent discovery rather than distinct operations.
Notable incidents
The 2024 US telecommunications intrusions affected multiple providers and reportedly touched lawful-intercept infrastructure, prompting joint federal advisories and sustained newsroom investigation [1·A2] [2·B2].
Targeting profile
Target selection has focused on telecommunications operators, government entities, and adjacent technology infrastructure across the United States, Southeast Asia, Latin America, and parts of Europe [4·B2] [5·C3].
Relationship graph
Entities, aliases, tooling, and victims as resolved on the Corvus Codex. Hover to isolate links, drag to explore, ⌘/Ctrl-scroll to zoom.
Defensive guidance
Prioritize edge-device patching and configuration audit, monitor for anomalous administrative tooling on network infrastructure, and constrain dwell time through segmentation and credential hygiene. Cross-reference MITRE ATT&CK technique coverage against observed TTPs.
R# analysis
On current evidence, attribution to the PRC is almost certainly correct; MSS sponsorship is likely but not confirmed in joint advisories. The cluster's reliance on edge-device exploitation and living-off-the-land tradecraft makes detection a function of infrastructure visibility rather than implant signatures, defenders with weak edge telemetry are structurally disadvantaged.
Evidence register
- A21CISA, FBI, NSA. Joint advisory on PRC-attributed compromises of US telecommunications infrastructure. Late 2024. cisa.gov.
- B22Reporting on Salt Typhoon US telecom intrusions across major outlets, late 2024. NYT, WSJ, Washington Post, corroborated across independent investigations.
- B23Kaspersky Lab. GhostEmperor: rootkit and tooling analysis. Vendor research, 2021 onward.
- B24Trend Micro. Earth Estries activity analysis: TTPs, tooling, targeting. Vendor research, 2023–2024.
- C35Regional intrusion reports across European and Latin American jurisdictions. Mixed-source; not all independently corroborated.
- B36Vendor and analyst characterizations of MSS sponsorship. Sponsorship-specific attribution not confirmed in joint advisories at time of assessment.
- B27Mandiant. UNC2286 tracking and overlap analysis. Vendor research, ongoing.
- B28ESET. FamousSparrow tracking: SparrowDoor backdoor and operations. Vendor research, 2021 onward.