Introduction
This report presents a cyber threat intelligence assessment of Salt Typhoon, a Chinese state-sponsored espionage actor that operates in support of the Ministry of State Security (MSS). The group has conducted sustained operations against global telecommunications and network infrastructure, with a strategic focus on obtaining and maintaining invisible access into high-value communications networks and government infrastructure.
Salt Typhoon's tradecraft emphasizes long-term access, persistence, and exploitation of network-edge infrastructure. The group has demonstrated a propensity for exploiting zero-days in products from vendors including Cisco, Ivanti, and Palo Alto Networks, as well as abusing native capabilities within network devices. This has included deploying unauthorized payloads within virtualized runtime environments such as Cisco Guest Shell and establishing covert Generic Routing Encapsulation (GRE) tunnels. Salt Typhoon leverages these capabilities to transform exposed edge infrastructure into persistent C2 platforms, all while maintaining a minimal host footprint.
This positioning lets the group operate at the boundary between trusted networks and the public internet, enabling network access and broad SIGINT collection while reducing reliance on traditional endpoint persistence. This access gives Salt Typhoon a durable platform for intelligence collection and foreign intelligence operations.
Executive summary
Salt Typhoon (aka: GhostEmperor, FamousSparrow, and Earth Estries) represents one of the more operationally disciplined state-sponsored espionage clusters currently active. Assessed to operate in support of Ministry of State Security (MSS) intelligence objectives, the group prioritizes silent network infiltration and broad communications interception; the group also engages in pre-positioning within critical infrastructure across various regions. A network of Chinese technology entities, including firms based in Sichuan Province, supports its operations by providing infrastructure and technical resources for concurrent campaigns across multiple regions and sectors.
A Serious and Persistent Threat to the Communications Backbone
Salt Typhoon's strategic advantage derives from its positioning within telecommunications and Internet backbone infrastructure. Recent operations demonstrate persistent access to Tier 1 Internet Service Providers and telecommunications routing infrastructure, giving operators downstream access to government networks and municipal communications at a scale that conventional endpoint compromise cannot replicate. This access has enabled the collection of Call Detail Records (CDRs), subscriber geolocation data, network authentication information, and law-enforcement records, while also allowing operators to map internal government and victim networks. This breadth of access is reflected in confirmed compromises spanning hundreds of organizations, including U.S. government and defence networks.
The Need for Preemptive Infrastructure Blocking
Salt Typhoon is fundamentally an infrastructure-access problem. The group can operate from network devices that generate virtually no host telemetry, keeping post-exploitation activity almost invisible to traditional endpoint monitoring. Effective defense therefore requires organizations to identify and track adversary infrastructure preemptively and block malicious infrastructure before operators can establish access. Identifying infrastructure associated with Salt Typhoon's targeting and C2 operations is critical to defending against its quiet persistence strategy.
Power by Proxy
U.S. and allied agencies assess Salt Typhoon’s activity as part of a broader Chinese intelligence effort involving both state organizations and commercial technology contractors. Rather than functioning solely through a conventional government cyber unit, the campaign draws on China's commercial cybersecurity ecosystem for vulnerability research, exploit development, infrastructure management, and operational support. This allows Chinese intelligence services to scale technical operations across multiple domains without requiring all capabilities to reside in-house within government organizations.
Chengdu's Shadow Network
The existence of this contractor-style relationship is now supported by direct U.S. government action and allied intelligence reporting. In January 2025, the U.S. Department of the Treasury sanctioned Sichuan Juxinhe Network Technology Co. Ltd., identifying the Sichuan-based cybersecurity company as directly involved in Salt Typhoon's compromise of multiple U.S. telecommunications and Internet service providers. Treasury further assessed that the MSS maintains strong relationships with computer network exploitation companies such as Juxinhe.
This relationship extends into a broader commercial contractor network operating out of Chengdu, Sichuan Province. A later joint advisory issued by CISA, the FBI, NSA, and international partners identified Sichuan Juxinhe, Beijing Huanyu Tianqiong Information Technology, and Sichuan Zhixin Ruijie Network Technology as a network of China-based entities associated with assisting the MSS’ broader cyber activity. The advisory assessed that the companies provide cyber-related products and services to Chinese intelligence organizations, including units of the MSS and People's Liberation Army (PLA). It further described the resulting operations as a global espionage system capable of tracking the communications and movements of targets through compromised telecommunications.
These companies also show indicators of commercial and technical overlap, such as interconnected leadership, shared intellectual property, and joint participation in state procurement bids. This structure provides the MSS with access to specialized capabilities and creates separation between intelligence requirements and the personnel executing individual technical functions:
Sichuan Juxinhe Network Technology Co., Ltd.: Sanctioned by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) in January 2025 for involvement in Salt Typhoon operations. The company provides custom exploit payloads, as well as network penetration and infrastructure management services to both the MSS and units of the People's Liberation Army (PLA).
Beijing Huanyu Tianqiong Information Technology Co., Ltd.: Designated in joint international intelligence advisories as an operational liaison and capability provider supporting state-sponsored network operations. Operational telemetry and corporate filings validated by Augur confirm the firm's deep integration within China's MSS contractor ecosystem. Corporate filings directly link the firm to Sichuan Zhixin Ruijie through majority ownership structures and key threat actors (specifically Yu Yang and Qiu Daibing) who co-filed Chinese state patents covering high-speed network packet inspection and automated data parsing, as well as research targeting edge device exploitation. This very research has been observed in Salt Typhoon operations in the wild, further corroborating the intersection of Salt Typhoon and China’s domestic security industry.

Sichuan Zhixin Ruijie Network Technology Co., Ltd.: Formally recognized by the Sichuan provincial government as a high-tech defense supplier, this firm functions as a commercial front and technical contractor delivering specialized big data collection tools. Corporate filings and state procurement records confirm active contracts with the People's Liberation Army (PLA) to supply custom mobile network simulation environments and automated vulnerability scanning frameworks targeting enterprise edge devices.
Targeting the Telecommunications Backbone
Salt Typhoon's operational goals prioritize systems that sit between large populations of users and the networks their communications transit, creating a collection engine that cannot be achieved through simple phishing alone.
The group centers its collection operations on global communications routing architecture. CISA reporting indicates that operators have targeted large backbone routers as well as provider-edge / customer-edge infrastructure, then used compromised devices and trusted network relationships to pivot into additional environments. The same reporting identifies persistent router modifications and the use of virtualized containers on network devices as campaign characteristics.
The resulting targeting spans several strategically significant areas:
- Telecommunications Infrastructure & Internet Service Providers: Telecommunications providers remain the central target set because compromise can provide significant downstream intelligence value. Salt Typhoon deploys custom tooling like GTPDOOR inside cellular core networks. This tool directly interacts with GPRS Tunnelling Protocol (GTP) control planes at international exchange points, allowing operators to trace subscriber SIM locations globally and read unencrypted SMS text streams without compromising individual mobile devices.
- Lawful Interception Infrastructure: Operators have targeted systems associated with lawful-intercept capabilities supported by telecommunications providers, specifically the Communications Assistance for Law Enforcement Act (CALEA) framework. By breaching wiretap request databases and law enforcement interception nodes inside major carriers, Salt Typhoon monitors which Chinese state actors and foreign diplomats Western federal authorities are actively investigating.
- Defense and Military Logistics Networks: Operators target administrative networks and remote access infrastructure across defense structures and sectors. A confirmed 2024 intrusion into a U.S. state Army National Guard network allowed actors to harvest administrator credentials and recon internal network topology. Operators also accessed state-level troop mobilization schedules and monitored troop training schedules undetected for approximately nine months.
- Government and Legislative Organizations: Intrusions into U.S. House of Representatives committee email systems and state-level Army National Guard networks were executed to map administrative networks and intercept communications between lawmakers and their staff. Silent persistence in legislative committee email systems, diplomatic routing networks, and executive communication channels also allowed operators to monitor sensitive trade negotiations and private communications between foreign officials.
- Transportation and Satellite Infrastructure: Augur tracking has also identified targeting across transportation and satellite communications environments. Salt Typhoon operators compromised ground station administration networks managing commercial satellite communications providers, like Viasat. Operators targeted remote management portals and backup communication links utilized by maritime and defense sectors, enabling the adversary to intercept failover traffic during primary network outages and silently reroute control telemetry to attacker-controlled infrastructure.
-
The significance of these victims is not the sensitivity of the information stolen from each organization. Salt Typhoon's threat comes from compromising infrastructure that connects otherwise separate targets. Access to a telecommunications provider can expose communications metadata and interception systems, creating unprecedented visibility into the government, military, and corporate users dependent upon that infrastructure. This enables the actor to collect at scale, maintaining access from a small number of strategically positioned network devices while victims remain unaware.
Adversary Overview
- Motive: Geopolitical cyber espionage, strategic counterintelligence monitoring, and upstream data interception.
- Targeted Sectors: Telecommunications infrastructure, defense logistics networks, aerospace and satellite ground stations, foreign legislative bodies, executive government communications, and high-end hospitality networks.
- Targeting Strategy: Opportunistic edge-device exploitation paired with post-exploitation routing and deep hardware persistence.
Salt Typhoon operates as an elite, Tier-1 state-espionage team under the oversight of the Ministry of State Security for the People's Republic of China. The cybersecurity industry tracks the group under designations including GhostEmperor (Kaspersky), Earth Estries (Trend Micro), FamousSparrow (ESET), UNC2286 (Mandiant), and OPERATOR PANDA (CrowdStrike). Emerging in its current operational form around 2019, the group functions as a premier cyber espionage organ for the Chinese intelligence apparatus, tasked with counterintelligence monitoring and deep network pre-positioning during periods of heightened tension.
Inside the Machine
Salt Typhoon relies on a blended force structure, combining internal MSS intelligence officers with a civilian network of software developers, vulnerability researchers, and infrastructure operators based in Chengdu, Sichuan Province. Intelligence disclosures indicate the broader threat ecosystem maintains an estimated operational strength of 50 to 100+ personnel distributed across distinct functional cells:
- Reconnaissance and Initial Access Teams: These specialized units conduct continuous reconnaissance against global internet-facing perimeters, specifically tracking external edge appliances along with core routing hardware. Operators compile target matrices by querying public device search engines and mapping active IP address allocations of Tier-1 ISPs. After identifying an exploitable asset, these operators execute zero-day or unpatched n-day exploit payloads targeting remote code execution and authentication-bypass vulnerabilities. After securing access, specialists harvest administrative credentials and pass control to post-exploitation operators.
- Exploitation and Tooling Engineers: Embedded as commercial technology contractors, these technical specialists perform deep reverse engineering on proprietary network device firmwares; namely Cisco IOS XE, Palo Alto PAN-OS, FortiOS, and Ivanti Connect Secure. The team constructs kernel-mode drivers alongside bespoke Linux binary implants tailored for virtualized environments like Cisco Guest Shell. They also engineer custom protocol dissectors such as GTPDOOR. Their primary mandate centers on developing memory-only execution vectors that bypass Endpoint Detection and Response (EDR) and evading native logging APIs.
- Infrastructure and DNS Operations Cell: These infrastructure handlers manage the setup and operational maintenance of command-and-control networks and data exfiltration pipelines. Operators lease virtual private servers across globally distributed hosting providers and configure multi-tiered proxy structures. They also register domain infrastructure using fabricated identities and stolen victim credentials to increase infrastructure legitimacy. To obscure operational traffic beneath routine enterprise activity, this cell sets up dead-drop resolvers on public cloud platforms like GitHub and Gmail. Operators establish covert Generic Routing Encapsulation (GRE) tunnels and modify device Access Control Lists (ACLs) to whitelist attacker-controlled IP spaces. These teams also abuse software misconfigurations to gain unauthorized Secure Shell services (SSH) on non-standard ports across compromised edge hardware.
- Data Exfiltration and Intelligence Analysts: Operating downstream of initial network breaches, this cell parses stolen intelligence streams. Operators interface directly with compromised law enforcement wiretap platforms (often via CALEA systems inside major telecommunications carriers) to extract Call Detail Records, harvest geolocation data via GPRS Tunnelling Protocol (GTP), and parse unencrypted VoIP audio streams. Operators then hand this telemetry to MSS analysts to track targets of concern and alert counterintelligence leadership to active federal law enforcement investigations.
Corporate records and intelligence indictments allowed Augur researchers to identify key individuals embedded within Salt Typhoon’s broader corporate network. Yin Kecheng operated C2 infrastructure, managed DNS routing, and orchestrated payload delivery across compromised telecommunications equipment. Zhou Shuai, known under the alias “Coldface,” functioned as an access broker and infrastructure builder, coordinating VPN portal compromises and harvesting administrative credentials while also registering proxy domains under fictitious identities. Yu Yang and Qiu Daibing occupied a different position within the ecosystem. Government filings identify Yu as a controlling shareholder of Sichuan Zhixin Ruijie and a shareholder of Beijing Huanyu Tianqiong, while Qiu held a 45-percent ownership stake in Huanyu Tianqiong. Both men also appear in records from the 2012 Cisco Networking Academy Cup at Southwestern Petroleum University in Sichuan; Qiu's team placed first in the competition and third nationally, while Yu's team placed second regionally.
Yu and Qiu’s subsequent technical work more strongly indicates that their present-day involvement extends beyond corporate administration. The pair are identified as collaborators on cybersecurity patents associated with Beijing Huanyu Tianqiong, and public records show that Yu was later employed by Sichuan Zhixin Ruijie. Their current patent activity focuses on network-security engineering and exploitation, while their earlier Cisco training links the pair directly to the networking technologies later targeted by Salt Typhoon. SentinelOne's research corroborates this, specifically linking their corporate ownership and association with the companies identified in the U.S. government advisory. These relationships provide a direct view of how the PRC integrates commercial expertise with state intelligence, enabling the MSS to bolster Salt Typhoon's operational capabilities far beyond those of a typical hacking group.
Operational Tradecraft
Salt Typhoon exhibits strict operational security and long-dwell persistence, often remaining inside compromised carrier networks for over three years without detection. Following initial boundary penetration, operators avoid dropping heavy host-based malware that could trigger Endpoint Detection and Response (EDR) agents. Instead, they prioritize native system administrative utilities—utilizing PowerShell, Windows Management Instrumentation Command-line (wmic), and Service Control Manager (sc.exe) to map internal network segments, query Active Directory domains, and register covert system services.
To evade defensive logging, operators execute PowerShell downgrade attacks to force execution in legacy environments, successfully bypassing the Windows Antimalware Scan Interface (AMSI). Command-and-control instructions and data exfiltration routes are obscured by leveraging public web platforms—including GitHub, Gmail, and File.io—as dead-drop resolvers. By routing malicious payloads through legitimate cloud services and encrypted TLS channels, Salt Typhoon blends command traffic into routine outbound corporate network activity.
Peacetime Persistence
Salt Typhoon's methodology now mirrors the operational doctrine being adopted across state-sponsored intelligence campaigns globally—similar to Volt Typhoon's staging within U.S. Navy infrastructure and Iranian actors like MuddyWater establishing silent holds across U.S. enterprise networks. During peacetime, Salt Typhoon functions as an intelligence engine; harvesting wiretap logs/Call Detail Records and high-value voice communications for intelligence agencies in China. While those intrusions are ongoing, the group simultaneously leaves deeply embedded implants across victim networks, allowing Chinese military and intelligence leadership the contingency ability to listen to or degrade foreign communications infrastructure during major geopolitical conflicts.
Augur Assessment
Augur's predictive infrastructure tracking confirms that Salt Typhoon maintains an active and continuously evolving command-and-control footprint that extends well beyond the public disclosure window. Across ten distinct infrastructure clusters attributed to Salt Typhoon identifiers, Augur has flagged over 300 malicious CIDR blocks — concentrated predominantly within GoDaddy-registered and velia.net-hosted ranges in the 85.195.x.x, 146.0.x.x, 185.19.x.x, and 37.61.x.x spaces; all predicted at maximum priority during a sustained April–October 2023 operational window directly coinciding with CISA / FBI reports of Salt Typhoon access across U.S. and allied telecommunications providers; Augur’s clustering engine simultaneously recorded co-location of multiple confirmed Salt Typhoon implant families across the same hosted ranges.
The consistent selection of /31 and /30 CIDR blocks across shared commercial hosting providers reflects deliberate infrastructure doctrine: provisioning C2 nodes within address space shared by legitimate enterprise and web hosting traffic lets operators structurally degrade conventional IP reputation blocking and force defenders into higher-cost detection methods. This approach mirrors the group's broader operational philosophy of operating within trusted network boundaries, whether that boundary is a compromised carrier's infrastructure or a GoDaddy-provisioned VPS hidden amid legitimate traffic.
Augur telemetry further confirms that Salt Typhoon's infrastructure remains operational as of March 2026. The IP 185.196.10[.]247, detected in March 2026 and later reported by six corroborating intelligence sources, represents the most recent confirmed indicator in Augur's dataset and is assessed with high confidence as an active operational node.
Earlier detections from August and September 2025, including 23.227.199[.]77, 85.195.89[.]94, 91.231.186[.]227, and 185.82.200[.]181, sourced across AlienVault OTX and PT Security, reinforce a pattern of continuous infrastructure refresh consistent with Salt Typhoon's documented preference for short-lived VPS nodes cycled across cheap, globally distributed providers; a pattern that peaked in November 2024, when Augur flagged 141.255.164[.]98 across ten independent intelligence sources, the highest corroboration density Augur has recorded against any single Salt Typhoon indicator.
Cluster analysis also surfaced an infrastructure overlap between Salt Typhoon and APT29 activity within a shared October 2021 cluster; a finding consistent with intelligence community assessments describing proximate or coincident targeting of Western government networks by Chinese and Russian state actors during the same period. Taken together, Augur's telemetry substantiates what public record suggests but cannot quantify: Salt Typhoon operators have not gone dormant. The group is actively maintaining and rotating its infrastructure, and organizations within its confirmed target sectors (telecommunications providers, defense networks, and government communications infrastructure) should treat the indicators above as live blocking priorities.
Mitigations
Edge & Perimeter Hardening
- Patch Prioritization: Maintain an accelerated vulnerability-management process for Internet-facing gateways and network appliances. Assess critical vulnerabilities affecting products from Citrix, Ivanti, Palo Alto Networks, Cisco, Fortinet, and Sophos immediately, and remediate them on an expedited timeline. Organizations assessed to fall within Salt Typhoon's targeting profile should apply an even more aggressive remediation threshold, treating known exploited vulnerabilities in exposed edge infrastructure as an immediate security flag.
- Isolate Management Planes: Move administrative interfaces for core switches, edge routers, and firewalls onto dedicated out-of-band management networks. Restrict access through tightly controlled ACLs and phishing-resistant MFA.
Network & Hardware Integrity Controls
- Container Environment Auditing: Routinely inspect Cisco environments for unauthorized Guest Shell activation and unexpected containerized processes operating within network appliances. Investigate any container, application, or execution environment not tied to an approved operational requirement as potential persistence.
- Firmware & Image Verification: Periodically verify network-device firmware and boot images against trusted vendor hashes and organizational gold images. Maintain the trusted reference images independently from the devices being monitored to prevent an attacker from altering both the device and its validation source.
- Configuration Integrity: Establish centralized baselines for router and firewall configurations and alert on unauthorized changes to digital infrastructure, including ACLs, routing tables, SSH services, administrative accounts, and tunnelling interfaces. Correlate configuration changes with approved maintenance activity, and treat unexplained modifications as potential compromise.
Identity & Intercept Architecture Isolation
- Zero-Trust Cloud Egress: Apply application-layer inspection and allowlisting to outbound connections from network infrastructure and administrative environments. Do not automatically trust legitimate cloud services, especially where they can support Living-off-the-Cloud (LotC) C2 or exfiltration channels.
- Protect Network Authentication: Ensure TACACS+ and RADIUS authentication traffic receives the strongest cryptographic protection the environment supports and cannot be passively captured from compromised network segments. Rotate administrative credentials immediately after a suspected compromise of network infrastructure.
- Isolate Intercept Systems: Segregate lawful-interception and communications-monitoring infrastructure from general carrier administration and production networks. Access should require dedicated management paths and independent authorization, limiting a compromised network device's ability to provide direct access to sensitive interception systems.
Infrastructure Intelligence & Blocking
- Preemptive Infrastructure Tracking: Continuously track Salt Typhoon-associated infrastructure and compare indicators against the organization's Internet-facing assets. This should include newly registered domains and IP infrastructure, as well as infrastructure observed probing or exploiting vulnerable edge devices.
- Preemptive Blocking: Incorporate Augured Salt Typhoon infrastructure into firewall and perimeter controls before observing an intrusion. Continuously update blocking to reflect adversary infrastructure changes, prioritizing higher-confidence indicators for automated enforcement.
Conclusion
Salt Typhoon operates beyond the visibility of conventional security monitoring. By targeting telecommunications routing paths that connect entire populations to their networks, the group collects at a scale no endpoint compromise can replicate while generating virtually no host-level telemetry. Defending against this threat starts before an intrusion occurs. Organizations within Salt Typhoon's confirmed target sectors must treat perimeter hardware as a critical security boundary and preemptively block adversary infrastructure before operators can establish their first foothold.
For questions or additional analysis, contact: research@augursecurity.com
References
- Malicious Apprentice | How Two Hackers Went From Cisco Academy to Cisco CVEs | SentinelOne
- Inside Salt Typhoon: China’s State-Corporate Advanced Persistent Threat


.png)
