216.73.217.22

Inside Salt Typhoon: China's State-Corporate Advanced Persistent Threat

· Published 25/09/2025 16:28 · Modified 25/09/2025 19:33

Export JSON

Essential information

Published
25/09/2025 16:28
Modified
25/09/2025 19:33
Tags
2025-09-25 CVE-2023-20198 CVE-2023-35082 advanced persistent threat china china chopper contractor ecosystem cve-2024-3400 cyber espionage demodex infrastructure targeting long-term persistence ministry of state security sigrouter telecommunications
Related entities
1 intrusion sets (apt), 16 techniques (mitre), 7 others

Description

Salt Typhoon is a Chinese state-sponsored cyber threat group aligned with the , specializing in long-term espionage operations targeting global infrastructure. Active since 2019, it has demonstrated advanced capabilities in exploiting network edge devices, establishing deep persistence, and harvesting sensitive communications data from telecom providers and critical infrastructure sectors. The group operates with MSS oversight and support from pseudo-private contractors, using front companies to obscure attribution. Salt Typhoon's campaigns utilize bespoke malware, living-off-the-land binaries, and stealthy router implants, with a targeting profile spanning the U.S., U.K., Taiwan, and EU. Their operations are notable for using publicly trackable domains registered with false U.S. personas, marking a rare lapse in tradecraft among advanced Chinese threat actors.

External references