EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/salt-typhoon-2024
078/430

File EL-0353CriticalOngoingEspionage Operation / Telecommunications Infrastructure Compromise

Salt Typhoon

Also filed as GhostEmperor · China US Telecom Wiretap System Breach

Salt Typhoon is a sophisticated, state-sponsored cyber espionage campaign targeting critical US telecommunications infrastructure. The operation aims to intercept and exfiltrate massive volumes of communication data, including voice, text, and metadata. Its focus on major carriers like AT&T and Verizon highlights a strategic interest in US national security and economic intelligence.

  • #china
  • #apt
  • #telecommunications
  • #wiretapping
  • #espionage
  • #critical-infrastructure
Notoriety8/10
Event
1 Sept 2024
Disclosed
1 Sept 2024
Target
Major US Telecommunications Providers
Actor
Salt Typhoon
Scale
Massive, estimated to be petabytes of communication data over time
Status
Ongoing

01Summary

The Salt Typhoon campaign represents a significant escalation in China's cyber espionage against Western critical infrastructure. The threat actors, operating under the aliases Salt Typhoon and GhostEmperor, have been observed compromising core network elements of major US telecom providers. Their methodology involves exploiting vulnerabilities within the supply chain or network management systems to establish persistent backdoors. The primary goal is not disruption, but deep, long-term surveillance, allowing the perpetrators to monitor communications streams. The sheer scale of the targeted infrastructure suggests a national-level intelligence mandate, aiming to build a comprehensive picture of US political, military, and corporate activities.

02Background

Historically, the US telecommunications sector has been a primary target for foreign intelligence services due to the sensitive nature of the data flowing through its networks. Previous incidents, such as those involving the compromise of network management systems, have raised concerns about foreign access to US communications. Salt Typhoon builds upon this history by targeting the core, high-value backbone of the industry.

03Key revelations

  1. 01The ability to intercept communications across multiple major US carriers simultaneously.
  2. 02The deep penetration into the core, backbone infrastructure of the US telecom sector.
  3. 03The sustained, long-term nature of the surveillance operation, indicating high state-level commitment.

04Technical analysis

The attack vector is believed to involve zero-day or N-day vulnerabilities in network equipment or management software (e.g., SNMP, Diameter protocol implementations). The malware deployed is designed for stealth and persistence, often residing deep within the network core. Techniques include man-in-the-middle (MITM) interception of signaling traffic and the exfiltration of metadata and encrypted payloads. The use of custom, highly specialized tools indicates significant state-level resources.

Attack vector
Supply Chain Compromise or Zero-Day Vulnerability Exploitation in Network Management Systems
Attack method
Persistent Backdoor Installation and Data Interception
Initial access
Compromised Vendor Credentials or Network Edge Exploitation
Lateral movement
Internal Network Pivoting via Compromised Core Routers
Persistence
Backdoors in Network Management Software/Firmware
Exfiltration
Encrypted, Low-and-Slow Data Tunneling
Tool / malware
Custom Interception Malware (Specific names are often classified/unknown)
Malware family
Interception/Spyware
Malware type
Spyware

Vulnerabilities exploited

  • Zero-day/N-day vulnerabilities in Telecom Protocols (e.g., Diameter, SS7)

MITRE ATT&CK techniques

  • T1071.001
  • T1567.002
  • T1027

05Threat actor

Salt Typhoon is characterized as a highly resourced, state-sponsored group operating under Chinese direction. Their profile suggests a focus on long-term, low-profile intelligence gathering rather than immediate financial gain or disruption, making them a sophisticated espionage threat.

Aliases

  • GhostEmperor

APT designations

  • APT41
  • China-linked APT

MITRE groups

  • T1071.001
  • T1567.002
  • T1027

Attribution sources

  • Industry Security Reports
  • Government Advisories

06Victims and impact

Additional victims

  • US Critical Infrastructure

Countries affected

  • United States

07Data exposed

Data types

  • Metadata (Call records, sender/receiver)
  • Voice Communications (Intercepted audio)
  • Text Messages (SMS/MMS)
  • Credentials
  • PII
  • Classified Communications

Notable documents

  • Internal Telecom Signaling Traffic Logs (Hypothetical)
  • Network Management System Configuration Files (Hypothetical)

08Financial damage

Damage is primarily measured in loss of national security and intelligence advantage, not direct financial theft.

09Timeline

  1. 2023-12-01Initial suspected compromise of network elements begins.
  2. 2024-09-01The breach is publicly disclosed by security researchers and government advisories.

10Reaction and fallout

Public reaction

The disclosure triggered immediate calls for stricter national cybersecurity standards and increased scrutiny of foreign technology vendors in critical infrastructure. Public concern focused on the erosion of privacy and national communication security.

Political impact

The incident heightened geopolitical tensions between the US and China, leading to increased calls for export controls on advanced networking technology and potential legislative action against foreign-owned telecom equipment.

Geopolitical consequences

It reinforces the concept of 'cyber sovereignty' and accelerates the trend of 'de-risking' supply chains in critical infrastructure, particularly concerning Chinese technology components.

11Legal

No immediate criminal charges were filed against the state actors, but the incident prompted internal reviews and potential regulatory mandates (e.g., CISA directives) within the US government.

Civil lawsuits

  • Potential class-action lawsuits regarding privacy violations (Future)

12Aftermath

Policy changes

  • Mandatory network segmentation for critical telecom components
  • Increased vetting of foreign technology vendors (e.g., 5G equipment)

Regulatory changes

  • Enhanced compliance requirements for Diameter and SS7 protocol security
  • Mandatory reporting of suspicious network activity to CISA

Security improvements

  • Implementation of end-to-end encryption across all signaling and user data layers
  • Adoption of Zero Trust Architecture (ZTA) within core networks

13Significance and legacy

Significance

Salt Typhoon is significant because it demonstrates the capability of a nation-state to achieve deep, persistent, and scalable surveillance within the most critical piece of modern infrastructure—the global telecommunications backbone. It sets a precedent for viewing telecom networks not just as commercial assets, but as primary military and intelligence targets.

Legacy

The incident will accelerate the global shift toward 'trusted' supply chains and the adoption of open-source, verifiable networking protocols. It solidifies the concept of 'cyber espionage' as a primary tool of great power competition, making network resilience a core national security concern.

14Disclosure and media

Authentication
Technical Analysis and Threat Intelligence Correlation

Media partners

  • Major Cybersecurity News Outlets

Publishing organisations

  • Government Intelligence Agencies (Advisories)

15Related files

Related events

  • China-linked APT attacks on US infrastructure

Inspired by

  • Snowden Archive Disclosures
  • NSA/PRISM Revelations

16Field notes

  1. 01The attack targets the signaling layer (metadata) as much as the content, which is often easier to intercept and analyze for patterns.
  2. 02The use of multiple aliases (Salt Typhoon, GhostEmperor) is a common tactic to confuse attribution efforts and mislead defenders.

17Resolution

The incident is currently under investigation by US federal agencies and industry security teams, with no definitive technical resolution or removal of the threat confirmed.

18Sources

Official documents

  • CISA Advisories on Telecom Security
  • US Department of Commerce Export Control Reports

References

  1. [1]Industry Threat Intelligence Reports
  2. [2]Government Cybersecurity Advisories
Fact sheetEL-0353

Dates

Event
1 Sept 2024
Started
1 Dec 2023
Discovered
1 Sept 2024
Disclosed
1 Sept 2024
Ongoing
Yes

Target

Organisation
AT&T, Verizon, Lumen (CenturyLink)
Type
Technology Company
Sector
Telecommunications
Country
United States
Gov. level
Federal

Actor

Name
Salt Typhoon
Type
Nation-State Actor
Nationality
Chinese
Nation-state
China
Affiliation
Chinese intelligence services/military units
Motivation
State-sponsored intelligence gathering, surveillance, and theft of sensitive telecommunications data.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Massive, estimated to be petabytes of communication data over time
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.