created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
Salt Typhoon
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).
| Attribute | Detail |
|---|---|
| ATT&CK ID | G1045 |
| Aliases | — |
| Attribution | China |
| Class | state |
| Active since | 2019 (per ATT&CK description) |
| ATT&CK entry created | 2025-02-24 |
| Techniques mapped | 15 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1021.004 |
SSH |
T1040 |
Network Sniffing |
T1048.003 |
Exfiltration Over Unencrypted Non-C2 Protocol |
T1098.004 |
SSH Authorized Keys |
T1110.002 |
Password Cracking |
T1136 |
Create Account |
T1190 |
Exploit Public-Facing Application |
T1572 |
Protocol Tunneling |
T1587.001 |
Malware |
T1588.002 |
Tool |
T1590.004 |
Network Topology |
T1602.002 |
Network Device Configuration Dump |
(First 12 of 15 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Ke3Chang — China-linked actor, same attribution class
- Mustang Panda — China-linked actor, same attribution class
- Earth Lusca — China-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G1045 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.