# Salt Typhoon - G1045

> As of 2026-09-25, Salt Typhoon - G1045 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning apt, malware. Also known as Salt Typhoon, FamousSparrow. ATT&CK coverage spans 43 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1190 (Exploit Public-Facing Application), T1071.001 (Web Protocols).

- **Nation:** China
- **Tracked threats:** 3
- **Categories:** APT, MALWARE
- **Also known as:** Salt Typhoon, FamousSparrow
- **As of:** 2026-09-25

## ATT&CK techniques observed

43 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (10), Command and Control (6), Persistence (6), Execution (5), Credential Access (3), Lateral Movement (3).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 3 of 3 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 3 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1543.003](https://intel.threadlinqs.com/technique/T1543.003) Create or Modify System Process: Windows Service — Persistence — observed in 2 of 3 tracked threats
- [T1574.001](https://intel.threadlinqs.com/technique/T1574.001) DLL — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1003.001](https://intel.threadlinqs.com/technique/T1003.001) LSASS Memory — Credential Access — observed in 1 of 3 tracked threats
- [T1014](https://intel.threadlinqs.com/technique/T1014) Rootkit — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 1 of 3 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 1 of 3 tracked threats
- [T1021.004](https://intel.threadlinqs.com/technique/T1021.004) SSH — Lateral Movement — observed in 1 of 3 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
- [T1040](https://intel.threadlinqs.com/technique/T1040) Network Sniffing — Credential Access — observed in 1 of 3 tracked threats
- [T1048.003](https://intel.threadlinqs.com/technique/T1048.003) Exfiltration Over Unencrypted Non-C2 Protocol — Exfiltration — observed in 1 of 3 tracked threats

## Tracked threats

- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)](https://intel.threadlinqs.com/threat/TL-2026-2649) — HIGH
- [SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV Detection, API Hooking, and Token Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2136) — MEDIUM
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2122) — CRITICAL

## Related CVEs

11 CVEs referenced by tracked Salt Typhoon - G1045 activity.

- [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2023-20273](https://intel.threadlinqs.com/cve/CVE-2023-20273)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045
