Salt Typhoon

THREAT ACTOR PROFILE

Salt Typhoon

Salt Typhoon

Salt Typhoon

Salt Typhoon is a China-linked espionage actor known for long campaigns against telecommunications and network infrastructure. It overlaps with activity vendors track as FamousSparrow and Earth Estries, and it favors quiet, long-term access to carrier and enterprise networks over noisy intrusions.

China

Telecommunications / Government

First seen

2019 or earlier

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

Where Salt Typhoon and FamousSparrow overlap

Attribution here needs care. Our record and several vendors treat Salt Typhoon, FamousSparrow, GhostEmperor and Earth Estries as overlapping China-linked activity, while ESET still tracks FamousSparrow as a group of its own. Reports under any of these names may describe the same operators or closely related ones.

We keep these mapped together in our list of known APTs we track, with the caveat that a FamousSparrow report is not automatically a Salt Typhoon report. Confirm the cluster before you merge indicators.

-

-

-

GROUP PROFILE

Quiet, long-term access to carrier networks

Salt Typhoon prioritizes stealthy, persistent access, credential capture and long-term collection from carrier and enterprise environments. Its hallmark is layered redirector infrastructure and quickly rotated domains to keep command-and-control alive.

The FamousSparrow side of this activity has been busy in 2026. ESET and others reported a shift toward government targets across Latin America, alongside an intrusion into an Azerbaijani oil and gas company. Earlier Salt Typhoon reporting focused on US telecoms and more than 80 countries.

Across the reporting, the way in is often a public-facing Microsoft Exchange server, followed by DLL sideloading to run modular backdoors.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

-

-

-

-

-

ATTACK LIFECYCLE

Exchange exploitation into sideloaded backdoors

The stages below come from 2026 reporting on Salt Typhoon and FamousSparrow activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

SparroWocky, SparrowDoor and SnappyBee

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Microsoft Exchange, through ProxyLogon and ProxyNotShell

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

Salt Typhoon

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

Salt Typhoon

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

Salt Typhoon

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Salt Typhoon

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

A new backdoor and a three-wave energy intrusion

Recent reporting on this activity centers on a new flagship backdoor and a persistent push into the energy sector.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

Salt Typhoon

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Salt Typhoon

IOC set, full IP, host and hash history.