Salt Typhoon — APT Profile
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).Also tracked as
Earth Estries, UNC2286, FamousSparrow, GhostEmperor, Opal Neutron
Tools & malware
- Crowdoor Backdoor
- Demodex Framework
- GhostSpider Backdoor
- HemiGate Backdoor
- JumbledPath Backdoor
- Masol RAT RAT
- SnappyBee Backdoor
- SparrowDoor Backdoor
- TrillClient Stealer
- win.sparrow_door Backdoor
- Zingdoor Backdoor
Recent claimed victims
- T-Mobile 2024-10-01
- Verizon 2024-10-01
- AT&T 2024-10-01
- US Army National Guard (unnamed state) 2024-03-01
Vendor research
- Earth Estries Targets Government, Tech for Cyberespionage Trend Micro
- You will always remember this as the day you finally caught FamousSparrow ESET
- GhostEmperor: From ProxyLogon to kernel mode Kaspersky
- Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions Trend Micro
- Breaking Down Earth Estries' Persistent TTPs in Prolonged Cyber Operations Trend Micro
- Treasury Sanctions Company Associated with Salt Typhoon and Hacker Associated with Treasury Compromise US Dept
- Weathering the storm: In the midst of a Typhoon Cisco