← All Threat Actors
Nation-State critical China (PRC)

Salt Typhoon

Chinese state-sponsored (MSS-linked) · Signals intelligence / lawful intercept compromise

Reports 2
Active Since 2019
Last Reported 10 May 2026
Sectors Targeted communications, government

Tactics, Techniques & Procedures (TTPs)

  • Compromise of telecoms lawful intercept infrastructure (CALEA systems)
  • Persistent access to carrier-grade network equipment
  • GhostEmperor rootkit for deep kernel-level persistence
  • Targeting of government and political communications
  • Lateral movement through peering relationships

Known Targets

US and European telecoms carriers (AT&T, Verizon)ISP lawful intercept systemsGovernment officials and political campaignsIntelligence community targets

Analyst Notes

Responsible for one of the most significant intelligence collection campaigns against Western telecoms infrastructure. Access in some carriers persisted for over 18 months after initial disclosure.

Also Known As

GhostEmperorFamousSparrowEarth Estries