ATT&CKGroupsSalt Typhoon

Salt Typhoon

G1045

Threat group.View on attack.mitre.org

About this group

Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).

Techniques used14

Procedure examples14

TechniqueProcedure example
T1021.004
SSH

Salt Typhoon has modified the loopback address on compromised switches and used them as the source of SSH connections to additional devices within the target environment, allowing them to bypass access control lists (ACLs).

T1040
Network Sniffing

Salt Typhoon has used a variety of tools and techniques to capture packet data between network interfaces.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

Salt Typhoon has exfiltrated configuration files from exploited network devices over FTP and TFTP.

T1098.004
SSH Authorized Keys

Salt Typhoon has added SSH authorized_keys under root or other users at the Linux level on compromised network devices.

T1110.002
Password Cracking

Salt Typhoon has cracked passwords for accounts with weak encryption obtained from the configuration files of compromised network devices.

T1136
Create Account

Salt Typhoon has created Linux-level users on compromised network devices through modification of `/etc/shadow` and `/etc/passwd`.

T1190
Exploit Public-Facing Application

Salt Typhoon has exploited CVE-2018-0171 in the Smart Install feature of Cisco IOS and Cisco IOS XE software for initial access.

T1572
Protocol Tunneling

Salt Typhoon has modified device configurations to create and use Generic Routing Encapsulation (GRE) tunnels.

T1587.001
Malware

Salt Typhoon has used custom tooling including JumbledPath.

T1588.002
Tool

Salt Typhoon has used publicly available tooling to exploit vulnerabilities.

T1590.004
Network Topology

Salt Typhoon has used configuration files from exploited network devices to help discover upstream and downstream network segments.

T1602.002
Network Device Configuration Dump

Salt Typhoon has attempted to acquire credentials by dumping network device configurations.

T1685.006
Clear Linux or Mac System Logs

Salt Typhoon has cleared logs including .bash_history, auth.log, lastlog, wtmp, and btmp.

T1686
Disable or Modify System Firewall

Salt Typhoon has made changes to the Access Control List (ACL) and loopback interface address on compromised devices.

Software1

Campaigns0

None recorded.

References2

  1. Cisco Salt Typhoon FEB 2025 Open source
    Cisco Talos. (2025, February 20). Weathering the storm: In the midst of a Typhoon. Retrieved February 24, 2025.
  2. US Dept. of Treasury Salt Typhoon JAN 2025 Open source
    US Department of Treasury. (2025, January 17). Treasury Sanctions Company Associated with Salt Typhoon and Hacker Associated with Treasury Compromise. Retrieved February 24, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.