Inside Salt Typhoon: China's State-Corporate Advanced Persistent Threat
Essential information
- Published
- 25/09/2025 16:28
- Modified
- 25/09/2025 19:33
- Tags
- 2025-09-25 CVE-2023-20198 CVE-2023-35082 advanced persistent threat china china chopper contractor ecosystem cve-2024-3400 cyber espionage demodex infrastructure targeting long-term persistence ministry of state security sigrouter telecommunications
- Related entities
- 1 intrusion sets (apt), 16 techniques (mitre), 7 others
Description
Salt Typhoon is a Chinese state-sponsored cyber threat group aligned with the Ministry of State Security, specializing in long-term espionage operations targeting global telecommunications infrastructure. Active since 2019, it has demonstrated advanced capabilities in exploiting network edge devices, establishing deep persistence, and harvesting sensitive communications data from telecom providers and critical infrastructure sectors. The group operates with MSS oversight and support from pseudo-private contractors, using front companies to obscure attribution. Salt Typhoon's campaigns utilize bespoke malware, living-off-the-land binaries, and stealthy router implants, with a targeting profile spanning the U.S., U.K., Taiwan, and EU. Their operations are notable for using publicly trackable domains registered with false U.S. personas, marking a rare lapse in tradecraft among advanced Chinese threat actors.