Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
The Salt Typhoon cyber espionage campaign has been making shocking headlines around the world, but especially in the US. This sophisticated, allegedly state-backed operation has been targeting critical infrastructure, government agencies, and key industries worldwide. Security researchers have linked this campaign to advanced persistent threat (APT) actors leveraging stealthy techniques to infiltrate and persist within high-value networks.
The campaign focused on long-term cyber espionage has been using stealthy intrusion methods, and data exfiltration to support geopolitical and economic agendas. Hackers associated with the campaign managed to break into some of the biggest US internet providers and data of millions has apparently been compromised. According to news reports, Salt Typhoon threat actors also targeted the phones of Donald Trump and Kamala Harris during the recent US elections
We've tried to make sense of everything that has gone down since the Nation-State actors have tried to establish their foothold in critical US infrastructure with our Salt Typhoon Cyber Attack Timeline.
From spear phishing campaigns to exploitation of zero-day vulnerabilities, the hackers have been using a variety of Tactics and Techniques in pursuit of sensitive information over the last few months.
Our Detailed Cyber Attack Timeline encapsulates, in depth, these series of incursions. The Salt Typhoon Cyber Attack Timeline summary is a visual representation of the key events, impact and actions taken in this massive cyber espionage campaign.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
Salt Typhoon is the name given by Microsoft to an alleged Chinese state-sponsored cyber espionage campaign that compromised the networks of multiple US telecommunications and internet providers. Rather than seeking ransom or destruction, the campaign was geared toward long-term intelligence collection, reportedly accessing call records, some private communications and systems used for court-authorised wiretap requests. A senior US senator described it as the worst telecom hack in the nation's history.
The campaign was first publicly disclosed by The Wall Street Journal on 25 September 2024, though US investigators reportedly began looking into it in the late spring of 2024 and the intruders had in some cases held access for a year or more. Disclosures, impact assessments and the US government response continued through late 2024 and into early 2025, with further technical findings published in February 2025.
US officials and security researchers have attributed the campaign to alleged Chinese state-sponsored actors linked to China's Ministry of State Security. In January 2025, the US Treasury's OFAC sanctioned a China-based company, Sichuan Juxinhe Network Technology, which it said was directly linked to Salt Typhoon, along with a Shanghai-based cyber actor, Yin Kecheng. China has routinely denied such allegations. The 'Salt Typhoon' name was coined by Microsoft.
Reporting indicated that at least nine US telecommunications companies were compromised, including AT&T, Verizon, Lumen Technologies, T-Mobile, Charter Communications, Consolidated Communications and Windstream. Several carriers later said they had contained the activity and detected no further nation-state access on their networks.
According to Cisco Talos, the attackers gained access to Cisco devices largely through compromised login credentials. Researchers also found that older and known Cisco vulnerabilities were exploited in some cases (CVE-2018-0171, CVE-2023-20198 and CVE-2023-20273) to reach unpatched devices. US officials highlighted weak controls, noting that in one telecom a single compromised administrator account had access to more than 100,000 routers.
Officials and reporting indicated the attackers accessed large volumes of call records and metadata, reportedly affecting the records of more than a million people, along with some private calls and texts of a smaller number of individuals primarily involved in government or political activity. The campaign also reportedly reached systems used for court-authorised US wiretap requests. End-to-end encrypted communications, such as those on Signal, were believed not to have been compromised.
According to The Washington Post, the campaign reportedly targeted the phones of Donald Trump and his running mate JD Vance, people working on Vice President Kamala Harris's campaign, and State Department officials. Officials noted the effort was not directly election-related, as the intruders had reportedly been inside the telecom systems months earlier, in some cases more than a year before. These points reflect media reporting and official statements.
Researchers attributed a range of custom tooling to the group. Trend Micro reported a backdoor called GhostSpider, alongside a Linux backdoor known as Masol RAT, a rootkit named Demodex, and a modular backdoor called SnappyBee. Cisco Talos separately documented custom malware it named JumbledPath, used to chain remote connections between targeted Cisco devices and attacker-controlled jump hosts.
No. Salt Typhoon was an intelligence-collection and espionage campaign rather than a ransomware or extortion operation, so no ransom was demanded. Its goal, according to officials and reporting, was long-term access to sensitive communications and records.
The FBI and CISA investigated and issued guidance, including urging senior officials and politicians to use only end-to-end encrypted communications. US agencies held a classified briefing for all senators, the FCC moved to require carriers to secure their networks, and the Treasury's OFAC imposed sanctions on Sichuan Juxinhe Network Technology and the cyber actor Yin Kecheng. Officials cautioned that the affected companies had not fully removed the intruders at the time of reporting.
The campaign shows how stolen credentials and unpatched, internet-facing equipment can give a capable adversary deep, persistent access to critical networks. The key lessons are rigorous patching of network devices, least-privilege design so no single account controls vast infrastructure, strong credential and access management, end-to-end encryption for sensitive communications, and readiness for stealthy nation-state intrusions. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.