Salt Typhoon
[Salt Typhoon](https://attack.mitre.org/groups/G1045) is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).(Citation: US Dept. of Treasury Salt Typhoon JAN 2025)(Citation: Cisco Salt Typhoon FEB 2025)
Properties
- stix_id
- intrusion-set--1c3dcf91-b859-4aae-a09c-ae26dc8b6390
- signal_observed_at
- 2026-09-11T17:54:59+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (16)
Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system log
Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system log
Adversaries may create an account to maintain access to victim systems.(Citation: Symantec WastedLocker June 2020) With a sufficient level of access,
Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gath
Adversaries may disable or modify system firewalls in order to bypass controls limiting network usage. Changes could be disabling the entire mechanism
Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The d
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of p
Adversaries may access network configuration files to collect sensitive data about the device and the network. The network configuration is a file con
Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network
Adversaries may gather information about the victim's network topology that can be used during targeting. Information about network topologies may inc
Adversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enabl
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into remote machines using Secure Shell (SSH). The adversary ma
Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hyperv
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A to
Software & Tools (1)
[JumbledPath](https://attack.mitre.org/software/S1206) is a custom-built utility written in GO that has been used by [Salt Typhoon](https://attack.mit
Explore this actor's full graph with Ninja Signal