Salt Typhoon has modified the loopback address on compromised switches and used them as the source of SSH connections to additional devices within the target environment, allowing them to bypass access control lists (ACLs).3
group
Salt Typhoon G1045
- Created
- 24 February 2025
- Last modified
- 31 July 2026
- Alias
- Salt Typhoon
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).[1][2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1045
Salt Typhoon has used a variety of tools and techniques to capture packet data between network interfaces.4
Salt Typhoon has exfiltrated configuration files from exploited network devices over FTP and TFTP.5
Salt Typhoon has added SSH authorized_keys under root or other users at the Linux level on compromised network devices.6
Salt Typhoon has cracked passwords for accounts with weak encryption obtained from the configuration files of compromised network devices.7
Salt Typhoon has created Linux-level users on compromised network devices through modification of /etc/shadow and /etc/passwd.8
Standing G1045
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
43rd percentile · 57% of 176 ATT&CK groups have more Enterprise techniques.
73rd percentile · 73% of 176 ATT&CK groups have this many tactics spanned or fewer.
23rd percentile · 77% of 176 ATT&CK groups have more tools and malware.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
26th percentile · 74% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G1045
404 distinct rules cover the 14 techniques recorded for this group. The 409 technique-to-rule mappings resolve to 404 distinct rules, because one rule can cover several techniques. 239 Sigma · 165 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org