
China’s Salt Typhoon Spies Are Still Hacking Telecoms—Now by Exploiting Cisco Routers
WiredWhen the Chinese hacker group known as Salt Typhoon was revealed last fall to have deeply penetrated major US telecommunications companies—ultimately breaching no fewer than nine of the phone carriers and accessing Americans' texts and calls in real time—that hacking campaign was treated as a four-alarm fire by the US government. “I think there's just a general under-appreciation for how aggressive they are being in turning telecommunications networks into Swiss cheese.” To carry out this latest campaign of intrusions, Salt Typhoon—which Recorded Future tracks under its own name, RedMike, rather than the Typhoon handle created by Microsoft—has targeted the internet-exposed web interfaces of Cisco's IOS software, which runs on the networking giant's routers and switches. Recorded Future found more than 12,000 Cisco devices whose web interfaces were exposed online, and says that the hackers targeted more than a thousand of those devices installed in networks worldwide. For those selected targets, Salt Typhoon configured the hacked Cisco devices to connect to the hackers' own command-and-control servers via generic routing encapsulation, or GRE tunnels—a protocol used to set up private communications channels—then used those connections to maintain their access and steal data. Hacking network appliances as entry points to target victims—often by exploiting known vulnerabilities that device owners have failed to patch—has become standard operating procedure for Salt Typhoon and other Chinese hacking groups.
History of this topic

Chinese espionage group Silk Typhoon has new tactics to target US networks
Firstpost
US Charges 12 Alleged Spies in China’s Freewheeling Hacker-for-Hire Ecosystem
Wired
US charges Chinese hackers in broad cyberespionage campaign
Associated Press
China-backed APT40 hacking group blamed for cyber attacks on Samoa
ABC
Under Trump, US Cyberdefense Loses Its Head
Wired
US Names One of the Hackers Allegedly Behind Massive Salt Typhoon Breaches
Wired
Beijing’s espionage campaign against the West
Live Mint
US Treasury slaps Chinese cybersecurity firm with sanctions for ties to Flax Typhoon hacking group
Firstpost
Beijing-based cyber group protests US sanctions for its alleged role in hacking incidents
Associated Press
The U.S. is considering a ban on a Chinese-made internet router – and it’s probably already in your home
The Independent
Chinese hack compromises more US telecom firms than previously known: Report
Hindustan Times
US sanctions China's Integrity Technology over alleged hacking sweep
Deccan Chronicle
US sanctions China’s Integrity Tech for ties to group Flax Typhoon’s alleged hacking of critical infrastructure
Live Mint
US sanctions Beijing-based cyber group for its alleged role in hacking incidents
India Today
Chinese hackers accessed workstations and documents in a ‘major’ cyber incident, Treasury says
Associated Press
Chinese Salt Typhoon cyberespionage targets AT&T, Verizon but networks secure, carriers say
The Hindu
9th Telecom Firm Targeted by Chinese Espionage: White House
Deccan Chronicle
White House: 9th telecom firm targeted in massive Chinese espionage campaign
India Today
A 9th telecoms firm has been hit by a massive Chinese espionage campaign, the White House says
Hindustan Times
A 9th telecoms firm has been hit by a massive Chinese espionage campaign, the White House says
Associated Press
A 9th telecoms firm has been hit by a massive Chinese espionage campaign, the White House says
The Independent
Tally of telecom firms hacked in massive Chinese espionage campaign rises
LA Times
Chinese national cyber centre says U.S. hacks stole trade secrets from tech firms
The Hindu
US is investigating potential national security risks posed by internet routers used by millions
CNN
Chinese 'Salt Typhoon' hackers breached 8 US telcos, still have access to systems, says top US official
Firstpost
US says Chinese hack of global telecom providers is ‘ongoing,’ Trump and Vance affected: Report
Hindustan Times
Chinese hackers compromised at least 8 US telecoms in Salt Typhoon hacking campaign, finds White House
Firstpost
US says ‘Salt Typhoon’ Chinese hacking group behind major metadata theft
Al Jazeera
US prioritises action against Chinese hacker group after massive metadata breach
India Today
At least eight US telecom firms compromised by Chinese hack campaign, White House says
The Independent
White House says at least 8 US telecom firms, dozens of nations impacted by China hacking campaign
Associated Press
Senators Warn the Pentagon: Get a Handle on China’s Telecom Hacking
Wired
Senators fume over response to ‘disturbing and widespread’ Chinese hack of US telecoms
Politico
The White House struggles to stop Chinese telecommunications hacks
Politico
White House official: 8 US telecom providers hacked by Chinese
CNN
FBI tells telecom firms to boost security following wide-ranging Chinese hacking campaign
Associated Press
FBI tells telecom firms to boost security following wide-ranging Chinese hacking campaign
The Independent
US officials still working to evict Chinese hackers from major US telecom networks
CNN
National security officials meet with US telecom execs to share intel on Chinese cyber-espionage campaign, White House says
CNN
US says China-linked hackers behind ‘significant’ cyberespionage campaign
Al Jazeera
Investigation into Chinese hacking reveals ‘broad and significant’ spying effort, FBI says
Associated Press
Chinese hackers had backdoor access to iPhones used by 2 Trump's presidential campaign officials
Firstpost
China hack enabled vast spying on US officials, likely ensnaring thousands of contacts
Live Mint
Chinese hackers gained access to huge trove of Americans’ cell records
Politico
Inside the investigation into a giant Chinese botnet
NPR
Justice Department disrupts vast Chinese hacking operation that infected consumer devices
Associated Press
China-backed hackers stepping up attacks on Taiwan, cybersecurity firm says
Al Jazeera
Chinese cyber-espionage campaign impacted FortiGate systems worldwide, says Dutch Military Intelligence
The Hindu
China is ‘prepositioning’ for future cyberattacks. The new NSA chief is worried
Live MintDiscover Related







































