Skip to content

๐Ÿ‡จ๐Ÿ‡ณ Salt Typhoon

Threat-actor battle card ยท maintained from public sources ยท last updated 2026-08-20 ยท also known as RedMike, OPERATOR PANDA, GhostEmperor, UNC5807

CategoryNation-state APT (espionage)
AttributionChina (PRC MSS / PLA-linked contractors, incl. Sichuan Juxinhe Network Technology)
First seenAt least 2021
StatusActive
Primary targetsTelecommunications, Government, Transportation, Lodging, Military

Overview

Salt Typhoon is a PRC state-sponsored espionage actor operating globally since at least 2021, subject of joint advisory AA25-239A (Aug 2025). Linked to Chinese contractors (Sichuan Juxinhe Network Technology, sanctioned by US Treasury Sep 2025) that service the PLA and Ministry of State Security. By August 2025 the FBI confirmed 200+ organisations in 80+ countries compromised; 600+ organisations globally notified of adversary interest in their systems. Allied spy agencies (CISA, FBI, NSA, and Five Eyes partners) publicly attributed three Chinese tech companies as infrastructure providers in 2025. In 2026 the campaign expanded into South American telecom carriers with new implants TernDoor, PeerTime, and BruteEntry. FBI director confirmed in February 2026 that threats from Salt Typhoon are "still very much ongoing" despite US sanctions on Sichuan Juxinhe. US Senate Commerce Committee called out AT&T and Verizon for non-cooperation as late as February 2026; US agencies have stated they cannot confirm the adversary has been fully evicted from US telecom networks as of mid-2026.

Tradecraft

  • Exploits vulnerabilities in telecom backbone routers โ€” provider-edge and customer-edge devices that lack EDR-class monitoring.
  • Modifies router firmware and configurations for persistent, stealthy, long-term access; firmware integrity checks rarely implemented at the provider level.
  • Objective: tap communications and movement data of high-value intelligence targets via ISP, telecom, and travel-sector intrusions.
  • Long dwell times (months to years); highly selective data collection rather than bulk exfiltration.
  • New 2026 implants โ€” TernDoor, PeerTime, BruteEntry โ€” observed in South American carrier infrastructure.

Notable victims

  • US: AT&T, Verizon, T-Mobile, Spectrum (Charter), Lumen, Consolidated Communications, Windstream โ€” 9 US telecoms confirmed by FBI (Aug 2025).
  • Data/cable: Digital Realty (data center) and Comcast (cable/broadband) assessed as likely victims.
  • Satellite: Viasat (US satellite comms) confirmed June 2025.
  • Global (6 continents): UK telecom affiliate, South African provider, Italian ISP, Thai telecom, Myanmar's Mytel network โ€” per Recorded Future mapping.
  • US government: NSA, DOD, and intelligence-community communications reportedly intercepted over the 2022โ€“2025 campaign.
  • Scope: 600+ organisations globally notified by CISA/FBI of adversary interest in their systems; actual confirmed compromise narrower.

Assessment

A strategic counter-intelligence threat rather than a smash-and-grab. The 2022โ€“2025 US telecom campaign was described by US officials as among the worst intelligence failures in American history. Defense centres on edge-router firmware integrity, configuration monitoring, end-of-life device replacement, and end-to-end encrypted communications for sensitive material. Not victim-enumerated by DLS โ€” tracked qualitatively on the APT watchlist. Congressional concern (Cantwell letter Feb 2026) suggests networks may remain partially compromised.

UK regulatory response (July 2026): The UK government developed a new telecoms security code specifically in response to the Salt Typhoon campaign; however, following lobbying coordinated by TechUK (the UK tech industry body), the code was weakened before adoption. Dropped provisions include: (1) treating all incoming signalling traffic as untrusted by default; (2) mandatory monthly equipment restarts that would flush memory-only malware from compromised devices; (3) accelerated timeline for securing broad-access service accounts (deferred from end-2028 to end-2029). Parliament has a 40-day scrutiny window before the weakened code takes effect (effective mid-July 2026). These are precisely the controls designed to detect and remove the persistent, memory-resident access methodology Salt Typhoon uses โ€” their removal represents a significant defensive regression on an active, confirmed intrusion vector. The Record

Sources

๐Ÿ—‚๏ธ Attacks & victims

All disclosed victims attributed to this actor, newest first.

No attacks recorded yet.


โ† All threat actors ยท Full victim database โ†’