China’s Salt Typhoon Spies Are Still Hacking Telecoms—Now by Exploiting Cisco Routers
1 month, 1 week ago

China’s Salt Typhoon Spies Are Still Hacking Telecoms—Now by Exploiting Cisco Routers

Wired  

When the Chinese hacker group known as Salt Typhoon was revealed last fall to have deeply penetrated major US telecommunications companies—ultimately breaching no fewer than nine of the phone carriers and accessing Americans' texts and calls in real time—that hacking campaign was treated as a four-alarm fire by the US government. “I think there's just a general under-appreciation for how aggressive they are being in turning telecommunications networks into Swiss cheese.” To carry out this latest campaign of intrusions, Salt Typhoon—which Recorded Future tracks under its own name, RedMike, rather than the Typhoon handle created by Microsoft—has targeted the internet-exposed web interfaces of Cisco's IOS software, which runs on the networking giant's routers and switches. Recorded Future found more than 12,000 Cisco devices whose web interfaces were exposed online, and says that the hackers targeted more than a thousand of those devices installed in networks worldwide. For those selected targets, Salt Typhoon configured the hacked Cisco devices to connect to the hackers' own command-and-control servers via generic routing encapsulation, or GRE tunnels—a protocol used to set up private communications channels—then used those connections to maintain their access and steal data. Hacking network appliances as entry points to target victims—often by exploiting known vulnerabilities that device owners have failed to patch—has become standard operating procedure for Salt Typhoon and other Chinese hacking groups.

History of this topic

Chinese espionage group Silk Typhoon has new tactics to target US networks
2 weeks, 1 day ago
US Charges 12 Alleged Spies in China’s Freewheeling Hacker-for-Hire Ecosystem
55 years, 2 months ago
US charges Chinese hackers in broad cyberespionage campaign
2 weeks, 6 days ago
China-backed APT40 hacking group blamed for cyber attacks on Samoa
1 month, 1 week ago
Under Trump, US Cyberdefense Loses Its Head
2 months ago
US Names One of the Hackers Allegedly Behind Massive Salt Typhoon Breaches
2 months, 1 week ago
Beijing’s espionage campaign against the West
2 months, 1 week ago
US Treasury slaps Chinese cybersecurity firm with sanctions for ties to Flax Typhoon hacking group
2 months, 2 weeks ago
Beijing-based cyber group protests US sanctions for its alleged role in hacking incidents
2 months, 2 weeks ago
The U.S. is considering a ban on a Chinese-made internet router – and it’s probably already in your home
2 months, 2 weeks ago
Chinese hack compromises more US telecom firms than previously known: Report
2 months, 2 weeks ago
US sanctions China's Integrity Technology over alleged hacking sweep
Trending News
2 months, 3 weeks ago
US sanctions China’s Integrity Tech for ties to group Flax Typhoon’s alleged hacking of critical infrastructure
2 months, 3 weeks ago
US sanctions Beijing-based cyber group for its alleged role in hacking incidents
2 months, 3 weeks ago
Chinese hackers accessed workstations and documents in a ‘major’ cyber incident, Treasury says
2 months, 3 weeks ago
Chinese Salt Typhoon cyberespionage targets AT&T, Verizon but networks secure, carriers say
2 months, 3 weeks ago
9th Telecom Firm Targeted by Chinese Espionage: White House
2 months, 3 weeks ago
White House: 9th telecom firm targeted in massive Chinese espionage campaign
Trending News
2 months, 3 weeks ago
A 9th telecoms firm has been hit by a massive Chinese espionage campaign, the White House says
2 months, 3 weeks ago
A 9th telecoms firm has been hit by a massive Chinese espionage campaign, the White House says
2 months, 3 weeks ago
A 9th telecoms firm has been hit by a massive Chinese espionage campaign, the White House says
2 months, 3 weeks ago
Tally of telecom firms hacked in massive Chinese espionage campaign rises
2 months, 3 weeks ago
Chinese national cyber centre says U.S. hacks stole trade secrets from tech firms
3 months ago
US is investigating potential national security risks posed by internet routers used by millions
3 months, 1 week ago
Chinese 'Salt Typhoon' hackers breached 8 US telcos, still have access to systems, says top US official
3 months, 1 week ago
US says Chinese hack of global telecom providers is ‘ongoing,’ Trump and Vance affected: Report
3 months, 2 weeks ago
Chinese hackers compromised at least 8 US telecoms in Salt Typhoon hacking campaign, finds White House
3 months, 2 weeks ago
US says ‘Salt Typhoon’ Chinese hacking group behind major metadata theft
3 months, 2 weeks ago
US prioritises action against Chinese hacker group after massive metadata breach
Trending News
3 months, 2 weeks ago
At least eight US telecom firms compromised by Chinese hack campaign, White House says
3 months, 2 weeks ago
White House says at least 8 US telecom firms, dozens of nations impacted by China hacking campaign
3 months, 2 weeks ago
Senators Warn the Pentagon: Get a Handle on China’s Telecom Hacking
55 years, 2 months ago
Senators fume over response to ‘disturbing and widespread’ Chinese hack of US telecoms
3 months, 3 weeks ago
The White House struggles to stop Chinese telecommunications hacks
Trending News
3 months, 3 weeks ago
White House official: 8 US telecom providers hacked by Chinese
3 months, 3 weeks ago
FBI tells telecom firms to boost security following wide-ranging Chinese hacking campaign
3 months, 3 weeks ago
FBI tells telecom firms to boost security following wide-ranging Chinese hacking campaign
3 months, 3 weeks ago
US officials still working to evict Chinese hackers from major US telecom networks
3 months, 3 weeks ago
National security officials meet with US telecom execs to share intel on Chinese cyber-espionage campaign, White House says
4 months ago
US says China-linked hackers behind ‘significant’ cyberespionage campaign
4 months, 1 week ago
Investigation into Chinese hacking reveals ‘broad and significant’ spying effort, FBI says
4 months, 1 week ago
Chinese hackers had backdoor access to iPhones used by 2 Trump's presidential campaign officials
4 months, 2 weeks ago
China hack enabled vast spying on US officials, likely ensnaring thousands of contacts
4 months, 2 weeks ago
Chinese hackers gained access to huge trove of Americans’ cell records
4 months, 2 weeks ago
Inside the investigation into a giant Chinese botnet
5 months, 3 weeks ago
Justice Department disrupts vast Chinese hacking operation that infected consumer devices
6 months, 1 week ago
China-backed hackers stepping up attacks on Taiwan, cybersecurity firm says
9 months ago
Chinese cyber-espionage campaign impacted FortiGate systems worldwide, says Dutch Military Intelligence
9 months, 1 week ago
China is ‘prepositioning’ for future cyberattacks. The new NSA chief is worried
9 months, 3 weeks ago

Discover Related