In September 2024, the FBI and CISA disclosed one of the most significant cyber espionage campaigns targeting U.S. critical infrastructure: Salt Typhoon. This operation compromised major telecommunications providers, breached government wiretapping systems, and established persistent access across global networks. Unlike typical cyberattacks seeking to steal customer data, Salt Typhoon focused on controlling communications infrastructure that billions rely on every day.
Salt Typhoon targeted some 80 nations in a sweeping hack of global telecom systems, with at least 600 organizations notified that the hackers had interest in their systems.
The Global Cyber Alliance’s new report, “Salt Typhoon Across the Internet: What AIDE Honeypots Reveal About a Persistent State-Linked Campaign,” uses AIDE data to demonstrate Salt Typhoon’s operational characteristics through observable attack patterns spanning 2+ years. Salt Typhoon has been publicly attributed to actors based in China and assessed as state-sponsored; AIDE’s findings focus only on behavioral evidence and do not directly attribute the activity to Chinese authorities.
Between August 2023 and August 2025, AIDE recorded more than 72 million China-origin attack attempts against decoy systems emulating telecommunications networks. Within this broader dataset, AIDE identified patterns consistent with Salt Typhoon’s tactics, techniques, and procedures (TTPs)—providing an empirical view of the campaign’s operational tempo and corroborating indicators described in public advisories by CISA, the FBI, and industry partners.
According to CISA and partner nation advisories, Salt Typhoon’s reach extends beyond telecommunications to government, transportation, lodging, and military infrastructure networks globally. This represents persistent access to critical infrastructure across 80+ countries—not just espionage, but the capability to monitor, disrupt, or manipulate essential services during peacetime or crisis.
Call to Action
Salt Typhoon is an active, evolving campaign requiring immediate action from infrastructure operators.
Critical Priority:
- Inventory all Internet-facing VPN systems
- Search logs for suspicious webshell activity patterns (ASP/ASPX/PHP anomalies)
- Enable comprehensive logging on remote access systems
High Priority:
- Patch Published Vulnerabilities per CISA Advisory AA25-239A
- Deploy Enhanced Monitoring
- Enable MFA and Restrict Protocols
Strategic Priorities:
- Deploy out-of-band management networks for isolated administrative access
- Implement default-deny firewall rules and network segmentation
- Conduct comprehensive threat hunts using provided IOC patterns
- Establish baseline monitoring for attack lifecycle indicators observed in AIDE data
Join the Fight Against Unwanted Internet Traffic
The invisible war against unwanted traffic can only be won collectively, with a shared understanding that a secure and trustworthy Internet is everyone’s responsibility, from infrastructure operators to everyday Internet users in our digital society.
Part of GCA’s Internet Integrity Program, the AIDE project has been continuously collecting data on unwanted IP address activity since 2019. This data provides deep insight into the volumes of unwanted traffic and enables precise tracking of emerging global threats. With this data, we continue to analyze Salt Typhoon and other cybercriminal or state-sponsored campaigns that exploit our networks disguised in the pervasive phenomenon of unwanted Internet traffic.
To accelerate this work, GCA has launched the AIDE Community. After years of exploring the AIDE repository through a research lens, the community is expanding to include investigators from organizations with the ability to influence the entire Internet ecosystem through collective action. We will soon open our data platform to key actors—network operators, national authorities, and research centers—who can drive change within their areas of responsibility.
If your organization can be part of this movement and you would like to join our community, contact us to get started.
In the meantime, please explore the full report to learn more about what AIDE data can discover.



