Rook Reports

Open-Source Intelligence
DOSSIER · THREAT GROUP

Salt Typhoon

Last assessed 16 Jun 2026 · Confidence: Moderate · Source range: A2–C3 · Referenced in 1 report

Salt Typhoon is a People's Republic of China-attributed cyber-espionage cluster that, in late 2024, US government agencies and major outlets disclosed had compromised multiple US telecommunications providers and lawful-intercept systems across an extended access period [1·A2] [2·B2]. The group is tracked under several aliases by different vendors — including Earth Estries (Trend Micro), FamousSparrow (ESET), GhostEmperor (Kaspersky), and UNC2286 (Mandiant) — with overlapping but not identical operational footprints [3·B2].

The cluster's operational signature combines exploitation of network-edge devices (routers and other infrastructure equipment), living-off-the-land lateral movement, and extended dwell times measured in months. Public reporting indicates target selection has focused on telecommunications operators, government entities, and adjacent technology infrastructure across the United States, Southeast Asia, Latin America, and parts of Europe [4·B2] [5·C3].

Attribution to the People's Republic of China is rated almost certainly based on joint US government statements; sponsorship specifically by the Ministry of State Security (MSS) is rated likely based on private-sector vendor research aligned with US-government characterizations but not confirmed in joint advisories [1·A2] [6·B3].

Background

Public activity attributed to the cluster now tracked as Salt Typhoon dates to approximately 2019, with predecessor footprints visible in earlier vendor reporting under different aliases [3·B2]. Across the following five-plus years, the group has been observed targeting telecommunications operators, government bodies, and technology infrastructure across multiple regions.

The September–October 2024 public disclosures by the US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation, the National Security Agency, and major outlets brought the cluster to broad public attention, attributing intrusions affecting multiple US telecommunications providers and lawful-intercept systems [1·A2] [2·B2].

Attribution

Joint US government statements characterized the responsible actor as affiliated with the People's Republic of China [1·A2]. Private-sector vendor research from multiple firms has independently identified the cluster as PRC-linked, with several vendors specifically associating activity with Ministry of State Security (MSS) sponsorship based on tooling, targeting, and tradecraft consistency [6·B3] [7·B2].

It is assessed as almost certainly the case that the cluster operates with PRC state direction, and as likely the case that the operating service is the MSS rather than an alternative service (e.g., Ministry of Public Security or People's Liberation Army element). The lower confidence on the specific service reflects the absence of confirmation in published joint advisories at the time of assessment.

Tactics, techniques, and procedures

Code on a developer's screen, representative of the technical tradecraft involved in long-dwell-time intrusions.
Long-dwell-time intrusions characteristically rely on living-off-the-land techniques and legitimate administrative tooling rather than novel implants. Photo: Markus Spiske / Unsplash

Documented TTPs cluster around three patterns:

  • Edge-device exploitation. Initial access is consistently observed through compromise of network-perimeter devices — particularly routers, including known-vulnerable Cisco and other vendor equipment — rather than through user endpoints [2·B2] [4·B2].
  • Living-off-the-land lateral movement. After initial access, the cluster has been observed using legitimate administrative tools and protocols for movement, minimizing distinct artifacts and complicating detection [4·B2].
  • Extended dwell time. Public reporting indicates dwell times measured in months across multiple intrusions, with some access periods extending across a year or more before discovery [1·A2] [2·B2].

These patterns align with MITRE ATT&CK techniques in the Initial Access (T1190), Lateral Movement (T1021), Defense Evasion (T1078, T1562), and Persistence (T1505) tactic categories. A full ATT&CK mapping is available in cited vendor reporting.

Tools and malware

Vendor research has documented the following families in association with the cluster:

  • Demodex — a Windows kernel rootkit observed in Kaspersky reporting [3·B2].
  • HEMIGATE and TrillClient — backdoors and information stealers documented in Trend Micro reporting [4·B2].
  • SparrowDoor — an ESET-tracked backdoor under the FamousSparrow alias [8·B2].
  • DeedRAT variant — a remote access trojan with shared lineage to other PRC-attributed tooling, observed across multiple intrusions.

Notable incidents

The most publicly visible operations attributed to the cluster:

  • 2024 US telecommunications intrusions. Disclosed in late 2024 by joint US government advisory, with major outlets identifying AT&T, Verizon, Lumen, and other carriers as affected. Targeting of lawful-intercept systems and political-campaign communications was specifically called out [1·A2] [2·B2].
  • Southeast Asian government compromises. Trend Micro and other vendors have documented multiple Southeast Asian government and telecommunications intrusions across 2022–2024 attributed to overlapping toolsets and infrastructure [4·B2].
  • European and Latin American operations. Reported activity in European and Latin American jurisdictions has been characterized as secondary in scale to the US operations [5·C3].

Targeting profile

Reported targeting concentrates on telecommunications carriers and infrastructure (the operational signature), government bodies, and adjacent technology providers. Geographic targeting is heavily weighted to the United States in the most recent public reporting, with secondary documented activity in Southeast Asia, parts of Europe, and Latin America [4·B2] [5·C3].

Targeting of political-campaign communications — specifically including communications associated with the 2024 US presidential campaigns — was a distinct sub-pattern called out in joint advisories [1·A2].

Defensive guidance

CISA issued mitigation guidance in late 2024 covering known-vulnerable edge devices and prioritized hardening for telecommunications and adjacent operators [1·A2]. The most relevant standing defensive measures, drawn from public guidance:

  • Patch router and edge-device firmware against known vulnerabilities; apply vendor-issued advisories for Cisco and other commonly compromised platforms.
  • Monitor for indicators of artifact deployment associated with documented Salt Typhoon tooling (vendor IOC lists referenced in cited research).
  • Audit lawful-intercept and administrative-access systems for unauthorized credential use and configuration drift.
  • Treat extended administrative-tool usage from edge devices as suspect; verify against expected administrative patterns.

R# analysis

Salt Typhoon's public emergence and the scale of the disclosed US telecommunications intrusions have shifted the strategic landscape around carrier infrastructure security and have been a recurring background element in Rook Reports cyber and competitive-intelligence pieces. The cluster's tradecraft — particularly the consistent edge-device exploitation pattern — informs assessments of autonomous-defense market positioning and vendor coverage models in adjacent Rook reporting.

Network

Connected entities and sources.

Associated aliases, observed tooling, target sectors, and the graded sources behind each claim — visualized as a network of typed relationships. Hover any node to highlight its neighbors; drag to rearrange.

Ctrl+wheel zoom · drag pan

Evidence register

  1. A2 CISA, FBI, NSA. Joint advisory and statements on PRC-attributed compromises of US telecommunications infrastructure. Late 2024. cisa.gov.
  2. B2 Reporting on Salt Typhoon US telecommunications intrusions across major outlets, late 2024. The New York Times, The Wall Street Journal, The Washington Post. Confirmed across multiple independent newsroom investigations.
  3. B2 Kaspersky Lab. GhostEmperor: rootkit and tooling analysis. Vendor research, 2021 onward.
  4. B2 Trend Micro. Earth Estries activity analysis: TTPs, tooling, and targeting. Vendor research, 2023–2024.
  5. C3 Various regional intrusion reports across European and Latin American jurisdictions. Mixed-source coverage; not all independently corroborated.
  6. B3 Vendor and analyst characterizations of MSS sponsorship. Multiple private-sector firms; sponsorship-specific attribution not confirmed in joint government advisories at time of assessment.
  7. B2 Mandiant. UNC2286 tracking and overlap analysis. Vendor research, ongoing.
  8. B2 ESET. FamousSparrow tracking: SparrowDoor backdoor and operations. Vendor research, 2021 onward.

Classification

Threat group State-sponsored PRC Espionage Telecommunications Edge-device exploitation Active