Salt Typhoon
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 27/03/2026 01:14
- Updated at
- 27/03/2026 01:14
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 4 reports, 78 attack patterns (mitre), 6 malware, 5 sectors, 9 countries, 65 indicators, 8 vulnerabilities (cve)
Description
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (4)
-
11 MITREs 1 Malware 4 Observables 1 APT
-
16 MITREs 1 APT
-
6 CVEs 31 MITREs 92 Observables 1 APT
-
16 MITREs 3 Malwares 1 APT
Attack patterns (MITRE) (78)
-
-
-
-
-
Network Topology usesT1590.004 MITRE
-
-
-
-
-
-
-
Malware (6)
-
POISONPLUG.SHADOW usesFamily
-
SNAPPYBEE usesFamily
-
JumbledPath uses
-
MASOL RAT usesFamily
-
ShadowPad - S0596 usesFamily
-
DeedRAT usesFamily
Sectors (5)
-
Government targets
-
Technology targets
-
Defense targets
-
Energy targets
-
Telecommunications targets
Countries (9)
-
Germany targets
-
Taiwan targets
-
Australia targets
-
New Zealand targets
-
Central African Republic targets
-
United States of America targets
-
South Africa targets
-
Canada targets
-
United Kingdom of Great Britain and Northern Ireland targets
Indicators (65)
-
solveblemten.comindicates -
verfiedoccurr.comindicates -
http://89.31.121.101:443/DisplayDialog.exeindicates -
servicecloudconnect.comindicates -
cloudprocenter.comindicates -
chekoodver.comindicates -
2d9107edad9f674f6ca1707d56619a355227a661163f18b5794326d4f81a2803indicates -
asparticrooftop.comindicates -
e-forwardviewupdata.comindicates -
hateupopred.comindicates -
http://89.31.121.101:443/dbindex.datindicates -
http://89.31.121.101:443/imfsbDll.dllindicates
Vulnerabilities (CVE) (8)
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the …
- Attack vector
- Network
- Published
- 23/10/2023
- Modified
- 21/12/2025
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected …
- Attack vector
- NETWORK
- Published
- 03/11/2021
- Modified
- 14/01/2026
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker …
- Attack vector
- Network
- Published
- 16/10/2023
- Modified
- 21/12/2025
A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
- Attack vector
- Network
- Published
- 23/09/2022
- Modified
- 27/05/2026
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
- Attack vector
- Network
- Published
- 25/03/2024
- Modified
- 21/12/2025