๐จ๐ณ Salt Typhoon¶
Threat-actor battle card ยท maintained from public sources ยท last updated 2026-08-20 ยท also known as RedMike, OPERATOR PANDA, GhostEmperor, UNC5807
Overview¶
Salt Typhoon is a PRC state-sponsored espionage actor operating globally since at least 2021, subject of joint advisory AA25-239A (Aug 2025). Linked to Chinese contractors (Sichuan Juxinhe Network Technology, sanctioned by US Treasury Sep 2025) that service the PLA and Ministry of State Security. By August 2025 the FBI confirmed 200+ organisations in 80+ countries compromised; 600+ organisations globally notified of adversary interest in their systems. Allied spy agencies (CISA, FBI, NSA, and Five Eyes partners) publicly attributed three Chinese tech companies as infrastructure providers in 2025. In 2026 the campaign expanded into South American telecom carriers with new implants TernDoor, PeerTime, and BruteEntry. FBI director confirmed in February 2026 that threats from Salt Typhoon are "still very much ongoing" despite US sanctions on Sichuan Juxinhe. US Senate Commerce Committee called out AT&T and Verizon for non-cooperation as late as February 2026; US agencies have stated they cannot confirm the adversary has been fully evicted from US telecom networks as of mid-2026.
Tradecraft¶
- Exploits vulnerabilities in telecom backbone routers โ provider-edge and customer-edge devices that lack EDR-class monitoring.
- Modifies router firmware and configurations for persistent, stealthy, long-term access; firmware integrity checks rarely implemented at the provider level.
- Objective: tap communications and movement data of high-value intelligence targets via ISP, telecom, and travel-sector intrusions.
- Long dwell times (months to years); highly selective data collection rather than bulk exfiltration.
- New 2026 implants โ TernDoor, PeerTime, BruteEntry โ observed in South American carrier infrastructure.
Notable victims¶
- US: AT&T, Verizon, T-Mobile, Spectrum (Charter), Lumen, Consolidated Communications, Windstream โ 9 US telecoms confirmed by FBI (Aug 2025).
- Data/cable: Digital Realty (data center) and Comcast (cable/broadband) assessed as likely victims.
- Satellite: Viasat (US satellite comms) confirmed June 2025.
- Global (6 continents): UK telecom affiliate, South African provider, Italian ISP, Thai telecom, Myanmar's Mytel network โ per Recorded Future mapping.
- US government: NSA, DOD, and intelligence-community communications reportedly intercepted over the 2022โ2025 campaign.
- Scope: 600+ organisations globally notified by CISA/FBI of adversary interest in their systems; actual confirmed compromise narrower.
Assessment¶
A strategic counter-intelligence threat rather than a smash-and-grab. The 2022โ2025 US telecom campaign was described by US officials as among the worst intelligence failures in American history. Defense centres on edge-router firmware integrity, configuration monitoring, end-of-life device replacement, and end-to-end encrypted communications for sensitive material. Not victim-enumerated by DLS โ tracked qualitatively on the APT watchlist. Congressional concern (Cantwell letter Feb 2026) suggests networks may remain partially compromised.
UK regulatory response (July 2026): The UK government developed a new telecoms security code specifically in response to the Salt Typhoon campaign; however, following lobbying coordinated by TechUK (the UK tech industry body), the code was weakened before adoption. Dropped provisions include: (1) treating all incoming signalling traffic as untrusted by default; (2) mandatory monthly equipment restarts that would flush memory-only malware from compromised devices; (3) accelerated timeline for securing broad-access service accounts (deferred from end-2028 to end-2029). Parliament has a 40-day scrutiny window before the weakened code takes effect (effective mid-July 2026). These are precisely the controls designed to detect and remove the persistent, memory-resident access methodology Salt Typhoon uses โ their removal represents a significant defensive regression on an active, confirmed intrusion vector. The Record
Sources¶
- CISA joint advisory AA25-239A โ Countering Chinese State-Sponsored Actors
- TechCrunch โ Salt Typhoon: everywhere that's been hit (Mar 2026 tracker)
- Nextgov/FCW โ US agencies assessed Chinese telecom hackers likely hit data centers and residential ISPs
- US Senate Commerce Committee press release โ experts agree US networks remain vulnerable
- Vectra AI โ Salt Typhoon TTPs, detection, defense
- Huntress โ Salt Typhoon threat actor profile
- The Record โ UK weakens telecoms defenses after industry lobbying (July 2026)
- Global Cyber Alliance โ Salt Typhoon Across the Internet (Dec 2025 comprehensive mapping)
- CyberScoop โ FBI: Threats from Salt Typhoon are 'still very much ongoing' (Feb 2026)
- Congress.gov CRS โ Salt Typhoon Hacks and Federal Response Implications
๐๏ธ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
No attacks recorded yet.