Activity timeline
Salt Typhoon - G1045 appears in 3 tracked threats between and ; the busiest month was 2026-08 with 2 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 2 of 3 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1543.003 Create or Modify System Process: Windows Service — Persistenceobserved in 2 of 3 tracked threats
- T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1003.001 LSASS Memory — Credential Accessobserved in 1 of 3 tracked threats
- T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 1 of 3 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 1 of 3 tracked threats
- T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 1 of 3 tracked threats
- T1021.004 SSH — Lateral Movementobserved in 1 of 3 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 3 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 1 of 3 tracked threats
- T1040 Network Sniffing — Credential Accessobserved in 1 of 3 tracked threats
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol — Exfiltrationobserved in 1 of 3 tracked threats
Tracked threats
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)HIGH
- SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV Detection, API Hooking, and Token ImpersonationMEDIUM
- FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange ExploitationCRITICAL