Cybersecurity researchers have unveiled extensive infrastructure overlaps between two prominent Chinese Advanced Persistent Threat (APT) groups, Salt Typhoon and UNC4841, revealing a coordinated campaign targeting telecommunications infrastructure and government systems across more than 80 countries.
Silent Push threat analysts disclosed their findings in September 2025, identifying 45 previously unreported domains linked to these state-sponsored operations.
Salt Typhoon, also known as GhostEmperor and FamousSparrow, gained notoriety for breaching at least nine U.S. telecommunications companies in 2024, compromising metadata for nearly every American and accessing court-authorized wiretapping systems.
The group operates under China’s Ministry of State Security (MSS) and specializes in exploiting zero-day vulnerabilities rather than conducting social engineering attacks.

The research began by analyzing command and control (C2) infrastructure from Trend Micro’s November 2024 report on Salt Typhoon’s malware arsenal, which includes the Demodex rootkit and Snappybee and Ghostspider backdoors.
Silent Push investigators identified distinctive patterns in domain registration data, discovering multiple domains registered using ProtonMail addresses with random character strings like “sdsdvxcdcbsgfe@protonmail.com” and “oklmdsfhjnfdsifh@protonmail.com.”
Infrastructure Analysis Reveals Systematic Operations
The investigation uncovered sophisticated operational security measures employed by both threat groups. Domains were registered using fictitious personas with English names and non-existent U.S.
Addresses, including “Tommie Arnold” at “1729 Marigold Lane, Miami, FL” and “Monica Burch” at “1294 Koontz Lane, Los Angeles, CA”. All identified addresses proved to be fabricated, demonstrating the group’s attention to maintaining false legitimacy.
Technical analysis revealed shared name servers across the infrastructure, including patterns using *.1domainregistry.com, *.orderbox-dns.com, *.monovm.com, and *.naracauva.com.ru.
The oldest identified domain, onlineeylity.com, dates back to May 2020, indicating sustained operations spanning five years.
UNC4841, previously known for exploiting Barracuda Email Security Gateway vulnerabilities in 2023, shares substantial infrastructure overlap with Salt Typhoon operations.
The groups’ similar targeting preferences focus on government entities, telecommunications providers, and corporate networks requiring long-term persistent access.
Silent Push researchers emphasized the significance of these legacy fingerprints, noting that no new websites matching these patterns have emerged in four months, which suggests the infrastructure may represent historical operations.

The research team identified additional unreported infrastructure but withheld details, citing ongoing operational security concerns.
Organizations potentially targeted by these Chinese espionage operations should immediately search DNS logs spanning the past five years for requests to identified domains and associated IP addresses.
The coordinated nature of Salt Typhoon and UNC4841 operations represents a persistent threat to critical infrastructure and sensitive government communications systems worldwide.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates