Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-08

Salt Typhoon - G1045

Also known as:Salt TyphoonFamousSparrow

As of 2026-09-25, Salt Typhoon - G1045 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning apt, malware. Also known as Salt Typhoon, FamousSparrow. ATT&CK coverage spans 43 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1190 (Exploit Public-Facing Application), T1071.001 (Web Protocols).

Tracked threats
31 critical · 1 high · 1 medium
First seen
2026-08-23
Last seen
2026-09-25
ATT&CK techniques
43across 3 of 3 threats
Related CVEs
11Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 3 tracked threat(s) · Categories: APT, MALWARE

Activity timeline

Salt Typhoon - G1045 appears in 3 tracked threats between and ; the busiest month was 2026-08 with 2 reports.

ATT&CK techniques observed

43 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (10), Command and Control (6), Persistence (6), Execution (5), Credential Access (3), Lateral Movement (3)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 2 of 3 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1543.003 Create or Modify System Process: Windows Service — Persistenceobserved in 2 of 3 tracked threats
  • T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1003.001 LSASS Memory — Credential Accessobserved in 1 of 3 tracked threats
  • T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 1 of 3 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 1 of 3 tracked threats
  • T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 1 of 3 tracked threats
  • T1021.004 SSH — Lateral Movementobserved in 1 of 3 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 3 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 1 of 3 tracked threats
  • T1040 Network Sniffing — Credential Accessobserved in 1 of 3 tracked threats
  • T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol — Exfiltrationobserved in 1 of 3 tracked threats

Tracked threats

Related CVEs

11 CVEs referenced by tracked Salt Typhoon - G1045 activity