Salt Typhoon
MITRE G1013Also known as FamousSparrow, RedMike, Earth Estries, UAT-9244, Salt Typhoon
Reports
15
First seen
Jul 23, 2025
Last seen
Aug 5, 2026
Motivation
Espionage, Geopolitical
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
×1×2
United States×2
Azerbaijan×1
United Kingdom×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1190 Exploit Public-Facing Application ×13T1566 Phishing ×9T1486 Data Encrypted for Impact ×5T1557 Man-in-the-Middle ×4T1021 Remote Services ×4T1195 Supply Chain Compromise ×4T1598 Phishing for Information ×4T1078 Valid Accounts ×4T1041 Exfiltration Over C2 Channel ×4T1110 Brute Force ×3T1003 OS Credential Dumping ×3T1505.003 Web Shell ×3
Indicators
filename ×47cve ×47hash_sha256 ×20domain ×19url ×14ip_v4 ×9email ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2026-20045 (exploited)CVE-2021-26829 (exploited)CVE-2021-26855 (exploited)CVE-2021-26857 (exploited)CVE-2021-26858 (exploited)CVE-2021-27065 (exploited)CVE-2021-43798 (exploited)CVE-2023-2868 (exploited)CVE-2023-3519 (exploited)CVE-2023-7102 (exploited)CVE-2024-21410 (exploited)CVE-2024-3400 (exploited)CVE-2025-0282 (exploited)CVE-2025-0994 (exploited)CVE-2025-12825 (exploited)CVE-2025-25257 (exploited)CVE-2025-26399 (exploited)CVE-2025-27915 (exploited)CVE-2025-38067 (exploited)CVE-2025-41244 (exploited)
Recent reports
High