ChinaWidely attributedUnknownMITRE G1045

Salt Typhoon

Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
1.3
Low signal strength
Mentions2
Sources1
High conf.1
Last seenJun 2026
First observed
2025-02-24
Last active
Origin
China
Aliases
1
Techniques
14
Campaigns
2
China

Attribution signals

2 mentions · 1 source
#1confirmedhigh
Unspecified
socradar
Jun 2026

"Brazil confirmed among 80+ compromised countries; active through Feb 2026"

#2maylow
Unspecified
infosecurity-magazine
Jun 2026

"Salt Typhoon's ongoing efforts may also involve stealing encrypted data to decrypt at a later date."

Hedge terms observed

confirmedmay