Reviewed identity mapping approved on this date.
Salt Typhoon
Tracked as
G1045
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Cataloged
IdentityTracking identifier: G1045
Cataloged
CVECVE-2024-3400 linked to this actor
Cataloged
CVECVE-2018-0171 linked to this actor
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.
Name map
Salt TyphoonCanonical Name
G1045Tracking Id
Loading CVEs, techniques, indicators, malware, victims, and activity...