SALT TYPHOON
EARTH ESTRIES
GHOSTEMPEROR
UNC2286
Threat IntelligenceAPTMarch 15, 202618 min read

Salt Typhoon: Threat Intelligence Profile

PRC state-sponsored (MSS) advanced persistent threat group conducting strategic espionage operations against major telecommunications providers, targeting lawful intercept systems to surveil high-value intelligence targets.

Scroll

Salt Typhoon / Earth Estries / GhostEmperor (also known as Earth Estries, GhostEmperor, FamousSparrow, UNC2286) is a state-sponsored advanced persistent threat group attributed to People's Republic of China (MSS), active since 2019. The group primarily targets telecommunications, government, technology, critical infrastructure sectors. It is tracked by MITRE ATT&CK as G1045.

Overview & Attribution

Salt Typhoon represents one of the most significant PRC cyber espionage operations ever publicly disclosed. The group's systematic targeting of US telecommunications infrastructure -- including lawful intercept (CALEA) systems at AT&T, Verizon, and T-Mobile -- has provided Chinese intelligence services with unprecedented access to communications metadata and content of high-value surveillance targets, including US government officials and political campaigns.

Threat Assessment

Salt Typhoon has been active since 2019, attributed to People's Republic of China (MSS). The group is known for targeting telecommunications, government, technology, and critical infrastructure using a combination of custom malware, rootkits, and exploitation of edge network devices.

Arsenal & Tools

Salt Typhoon employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on telecommunications, government, technology, critical infrastructure sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted intrusion operations, leveraging both zero-day exploits and commodity tooling to achieve persistent access to lawful intercept infrastructure and call detail record databases.

Operational Pattern

Salt Typhoon is characterized by persistent, long-term access operations within telecom provider networks. Once inside, the group targets lawful intercept (CALEA) systems, call detail record databases, and network management infrastructure to conduct surveillance of specific high-value targets without deploying broadly destructive capabilities.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1190 Exploit Public-Facing ApplicationExploitation of vulnerabilities in VPN appliances, email gateways, and telecom infrastructure
ExecutionT1059 Command and Scripting InterpreterPowerShell and cmd.exe for post-exploitation command execution
Command and ControlT1071 Application Layer ProtocolHTTPS-based C2 communications blended with legitimate traffic
ExfiltrationT1048 Exfiltration Over Alternative ProtocolData exfiltration through encrypted channels to avoid network monitoring
PersistenceT1547 Boot or Logon Autostart ExecutionRegistry modifications and scheduled tasks for long-term persistence
Defense EvasionT1014 RootkitDemodex rootkit for kernel-level stealth and detection evasion

Notable Campaigns

Salt Typhoon has been linked to multiple significant campaigns. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Known Indicators
  • ghfrankenstein[.]com (C2 domain)
  • ffraborede[.]com (C2 domain)
  • zfrankenstein[.]com (C2 domain)
  • 185.216.32[.]186 (C2 IP)
  • 103.159.132[.]80 (C2 IP)

Detection & Defense

Defend Against Salt Typhoon

Mjolnir Security provides specialized capabilities to detect and respond to Salt Typhoon operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for Salt Typhoon TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of Salt Typhoon campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: March 15, 2026