Overview 29 indicators
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).
| ipv4 | 15 | G1045.json |
| domain | 14 | G1045-domain.txt |
Techniques 14 ATT&CK
Open in ATT&CK Navigator → or download the layer (14 techniques, layer 4.5)
- T1021.004 SSH
- T1040 Network Sniffing
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
- T1098.004 SSH Authorized Keys
- T1110.002 Password Cracking
- T1136 Create Account
- T1190 Exploit Public-Facing Application
- T1572 Protocol Tunneling
- T1587.001 Malware
- T1588.002 Tool
- T1590.004 Network Topology
- T1602.002 Network Device Configuration Dump
- T1685.006 Clear Linux or Mac System Logs
- T1686 Disable or Modify System Firewall
Software 1
Principal sources 8 reports
Ranked by how many of this actor's indicators each report brought in.
- 25securelist.com/ghostemperor-from-proxylogon-to-kernel-…
- 2welivesecurity.com/en/eset-research/you-will-always-rememb…
- 2virustotal.com/gui/ip-address/45.131.179.24/relations
- 2virustotal.com/gui/ip-address/43.254.216.195/relations
- 2virustotal.com/gui/file/b696fe2f31279af1e006d89beb0ff0…
- 2sygnia.co/blog/ghost-emperor-demodex-rootkit
- 2virustotal.com/gui/ip-address/193.239.86.168/relations
- 2virustotal.com/gui/file/f81a2e8a2a272e0bdae4e267fa220d…
Related groups 1
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 29 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
welivesecurity.com/en/eset-research/you-will-always-rememb… · virustotal.com/gui/ip-address/45.131.179.24/relations · virustotal.com/gui/ip-address/43.254.216.195/relations · virustotal.com/gui/file/b696fe2f31279af1e006d89beb0ff0…
domain amelicen.com ipv4 103.85.25.166:8444 -
sygnia.co/blog/ghost-emperor-demodex-rootkit · virustotal.com/gui/ip-address/193.239.86.168/relations · virustotal.com/gui/file/f81a2e8a2a272e0bdae4e267fa220d…
dateupdata.com imap.dateupdata.com -
securelist.com/ghostemperor-from-proxylogon-to-kernel-…
domain aftercould.com domain datacentreonline.com domain freedecrease.com domain game.newfreepre.com domain imap.newlylab.com domain imap.webdignusdata.com domain mail.reclubpress.com domain newfreepre.com domain newlylab.com domain reclubpress.com domain webdignusdata.com ipv4 107.148.165.158:443 ipv4 107.148.165.158:80 ipv4 154.223.135.214:443 ipv4 154.223.135.214:80 ipv4 27.102.113.240:443 ipv4 27.102.113.240:80 ipv4 27.102.113.57:443 ipv4 27.102.113.57:80 ipv4 27.102.114.55:443 ipv4 27.102.114.55:80 ipv4 27.102.115.51:443 ipv4 27.102.115.51:80 ipv4 27.102.129.120:443 ipv4 27.102.129.120:80
Further reading 11
- attack.mitre.org/groups/G1045
- blog.talosintelligence.com/salt-typhoon-analysis
- home.treasury.gov/news/press-releases/jy2792
- virustotal.com/gui/ip-address/193.239.86.168/relations
- sygnia.co/blog/ghost-emperor-demodex-rootkit
- virustotal.com/gui/file/f81a2e8a2a272e0bdae4e267fa220d…
- virustotal.com/gui/ip-address/45.131.179.24/relations
- virustotal.com/gui/ip-address/43.254.216.195/relations
- securelist.com/ghostemperor-from-proxylogon-to-kernel-…
- virustotal.com/gui/file/b696fe2f31279af1e006d89beb0ff0…
- welivesecurity.com/en/eset-research/you-will-always-rememb…