Salt Typhoon
Also reported as GhostEmperor, FamousSparrow, UNC2286, Earth Estries, RedMike and 2 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1190 6 reports in ATT&CK
- T1059.003 3 reports reports only
- T1068 3 reports reports only
- T1082 3 reports reports only
- T1095 3 reports reports only
- T1005 2 reports reports only
- T1021 2 reports reports only
- T1033 2 reports reports only
- T1036.004 2 reports reports only
- T1041 2 reports reports only
Show all 94 techniques Show fewer
- T1047 2 reports reports only
- T1055.001 2 reports reports only
- T1059.001 2 reports reports only
- T1070.004 2 reports reports only
- T1070.009 2 reports reports only
- T1071.001 2 reports reports only
- T1078.002 2 reports reports only
- T1083 2 reports reports only
- T1105 2 reports reports only
- T1106 2 reports reports only
- T1140 2 reports reports only
- T1482 2 reports reports only
- T1543.003 2 reports reports only
- T1547.001 2 reports reports only
- T1571 2 reports reports only
- T1573.001 2 reports reports only
- T1574.001 2 reports reports only
- T1587.001 2 reports in ATT&CK
- T1608.001 2 reports reports only
- T1620 2 reports reports only
- T1003.001 1 report reports only
- T1003.003 1 report reports only
- T1008 1 report reports only
- T1012 1 report reports only
- T1020 1 report reports only
- T1025 1 report reports only
- T1027.007 1 report reports only
- T1027.009 1 report reports only
- T1027.010 1 report reports only
- T1027.013 1 report reports only
- T1030 1 report reports only
- T1036 1 report reports only
- T1036.001 1 report reports only
- T1036.005 1 report reports only
- T1036.008 1 report reports only
- T1039 1 report reports only
- T1049 1 report reports only
- T1053.005 1 report reports only
- T1055 1 report reports only
- T1057 1 report reports only
- T1071 1 report reports only
- T1078 1 report reports only
- T1087 1 report reports only
- T1087.001 1 report reports only
- T1087.002 1 report reports only
- T1090.001 1 report reports only
- T1090.002 1 report reports only
- T1091 1 report reports only
- T1113 1 report reports only
- T1120 1 report reports only
- T1134 1 report reports only
- T1134.002 1 report reports only
- T1189 1 report reports only
- T1195 1 report reports only
- T1203 1 report reports only
- T1204.004 1 report reports only
- T1480.002 1 report reports only
- T1505.003 1 report reports only
- T1518.001 1 report reports only
- T1547 1 report reports only
- T1559 1 report reports only
- T1564.001 1 report reports only
- T1564.003 1 report reports only
- T1564.010 1 report reports only
- T1566.001 1 report reports only
- T1566.002 1 report reports only
- T1566.003 1 report reports only
- T1569.002 1 report reports only
- T1570 1 report reports only
- T1572 1 report in ATT&CK
- T1573.002 1 report reports only
- T1574 1 report reports only
- T1583.003 1 report reports only
- T1583.004 1 report reports only
- T1584 1 report reports only
- T1588.001 1 report reports only
- T1588.002 1 report in ATT&CK
- T1588.005 1 report reports only
- T1590 1 report reports only
- T1595 1 report reports only
- T1608.002 1 report reports only
- T1659 1 report reports only
- T1665 1 report reports only
- T1680 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2012-5687
- CVE-2014-4404 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-2051 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-18368 KEV
Show all 86 CVEs Show fewer
- CVE-2017-5638 KEV ransomware
- CVE-2018-0171 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2019-0708 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-16759 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-14882 KEV
- CVE-2020-17530 KEV
- CVE-2020-2551 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1879 KEV
- CVE-2021-21166 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-31805
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-36934 KEV
- CVE-2021-38647 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-3236 KEV
- CVE-2022-34305
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-47966 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-20273 KEV
- CVE-2023-26360 KEV
- CVE-2023-2868 KEV
- CVE-2023-36884 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2024-20399 KEV
- CVE-2024-21887 KEV ransomware
- CVE-2024-26229
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-42009 KEV
- CVE-2024-9680 KEV ransomware
- CVE-2025-0282 KEV ransomware
- CVE-2025-0994 KEV
- CVE-2025-21590 KEV
- CVE-2025-29824 KEV ransomware
- CVE-2025-32433 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-5777 KEV ransomware
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
- CVE-2026-1281 KEV
- CVE-2026-1340 KEV
- CVE-2026-21509 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Salt Typhoon, GhostEmperor - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Salt Typhoon, GhostEmperor - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ShadowPad (Malware Family)
-
Salt Typhoon, GhostEmperor - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Salt Typhoon, GhostEmperor - Threat Group Cards: A Threat Actor Encyclopedia
Show all 76 reports Show fewer
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
The original link failed its last check. Original publisher Detailsfor NCSC-MAR-SparrowDoor.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t32021
-
MoonBounce_ the dark side of UEFI firmware _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MoonBounce_ the dark side of UEFI firmware _ Securelist
-
MoonBounce- the dark side of UEFI firmware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MoonBounce- the dark side of UEFI firmware
-
GhostEmperor_technical-details_PDF_eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor GhostEmperor_technical-details_PDF_eng
-
GhostEmperor- From ProxyLogon to kernel mode
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GhostEmperor- From ProxyLogon to kernel mode
-
FamousSparrow_ A suspicious hotel guest _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FamousSparrow_ A suspicious hotel guest _ WeLiveSecurity
-
FamousSparrow- A suspicious hotel guest
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FamousSparrow- A suspicious hotel guest
-
GhostEmperor- Chinese-speaking APT targets high-profile victims using unknown rootkit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GhostEmperor- Chinese-speaking APT targets high-profile victims using unknown rootkit
Newest first. Details opens the report in Explore.