Salt Typhoon

☆ pin
MITRE G1013Also known as FamousSparrow, RedMike, Earth Estries, UAT-9244, Salt Typhoon
Reports
15
First seen
Jul 23, 2025
Last seen
Aug 5, 2026
Motivation
Espionage, Geopolitical

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×1
×2
United States×2
Azerbaijan×1
United Kingdom×1

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1190 Exploit Public-Facing Application ×13T1566 Phishing ×9T1486 Data Encrypted for Impact ×5T1557 Man-in-the-Middle ×4T1021 Remote Services ×4T1195 Supply Chain Compromise ×4T1598 Phishing for Information ×4T1078 Valid Accounts ×4T1041 Exfiltration Over C2 Channel ×4T1110 Brute Force ×3T1003 OS Credential Dumping ×3T1505.003 Web Shell ×3

Indicators

filename ×47cve ×47hash_sha256 ×20domain ×19url ×14ip_v4 ×9email ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

High

Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says

The Record (Recorded Future News)
High

InfraTrust Pulse identifies 61 infrastructure vulnerabilities admins should prioritize

Bleeping Computer
High

UK weakens telecoms defenses against Chinese hackers after industry pushback

The Record (Recorded Future News)
High

Threats to the 2026 FIFA World Cup: Physical Security, Cyber, and Influence Operations Risk Assessment

Recorded Future Insikt
High

ESET APT Activity Report Q4 2025–Q1 2026

ESET WeLiveSecurity
Critical

Azerbaijani Energy Firm Targeted in Multi-Wave Microsoft Exchange Exploitation Campaign

The Hacker News
High

State-Sponsored Actors: Operational Tradecraft and Incident Response Strategy

Cisco Talos
Critical

UAT-8302: China-nexus APT targeting government entities with custom malware

Cisco Talos
Critical

U.S. Public Sector Under Siege: Q1 2026 Threat Intelligence Report

Trend Micro Research
High

2025 Cloud Threat Hunting and Defense Landscape

Recorded Future Insikt
Medium

Risky Business #824 — Microsoft's Secure Future is looking a bit wobbly

Risky Business
High

CERT-EU Cyber Brief January 2026 – Espionage, Ransomware, and Critical Vulnerabilities

CERT-EU Threat Intel
High

ESET APT Activity Report Q2 2025–Q3 2025

ESET WeLiveSecurity
High

Cyber Brief October 2025 – Espionage, Disruption, Data Breaches, and Supply Chain Threats

CERT-EU Threat Intel
High

Risky Business #799 — Multiple critical vulnerabilities and breaches across tech vendors

Risky Business

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.