Salt Typhoon
G10451 reportsaliases · Salt Typhoon
1
Reports
0
Techniques
0
Tactics
2
Countries
n/a
Hunt coverage
1
Aliases
Analyst assessment — key judgments
- Primary targeting: CN, US.
- Activity declining: 0 report(s) in last 30d vs 1 prior (-100%).
- Assessment confidence: n/a.
Activity & trend
DecliningLast 30d: 0 vs 1 prior (-100%)· first reported 2026-08-05 · last 2026-08-05
0
7d
0
30d
1
90d
1
All
0.1
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
Targeting lost
CNUSOverview
Analyst triage
Intelligence summary
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).(Citation: US Dept. of Treasury Salt Typhoon JAN 2025)(Citation: Cisco Salt Typhoon FEB 2025)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- No ATT&CK techniques associated yet.
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|