Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Salt Typhoon

🇨🇳Salt Typhoon

🇨🇳 Salt Typhoon is a tracked threat actor in the Clankerusecase corpus. Attributed to CN. Primary motivation: State. We map 26 detection use cases to this actor across 48 MITRE ATT&CK techniques, with 3 threat-intel articles citing them. Active in our corpus from 2026-03-05 to 2026-05-28.

crit 3
View full actor card → All threat actors MITRE ATT&CK group spec (G1045) ↗
26Use cases
3Articles
48Techniques
1IOCs

Known aliases

Salt TyphoonGhostEmperorFamousSparrowEarth Estries

Top techniques

All other tracked techniques

Detection use cases (26)

Salt Typhoon (GhostEmperor/Earth Estries) DLL side-load of Demodex/ShadowPad/SparrowDoor from staging dirs AI · profile SΣDD Salt Typhoon / Earth Estries data exfiltration via curl upload to public file-sharing services AI · profile SΣDD Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency Bespoke axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Bespoke axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal Trusted vendor binary / installer launching unusual children Internal Non-browser process posting to Slack Web API (LaxGopher C2) Bespoke Non-browser process posting to Discord API (RatGopher C2) Bespoke Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) MITRE match Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) MITRE match Authentication not detected on admin API endpoint MITRE match AWS S3 bucket ACL / policy made public MITRE match DNS tunneling / TXT-heavy domain queries MITRE match Excessive resource consumption of third-party API MITRE match GitHub personal access token created MITRE match GitHub SSH key added from suspicious IP MITRE match GitLab personal access token generated MITRE match JWT authentication bypass attempt MITRE match

Threat-intel articles (3)

Tracked indicators

IP addresses (1)

43.231.113.50