Cisco Confirms Exploitation of Telecom Networks by Salt Typhoon APT Group

Listen to this Post

2025-02-21

In a new development confirmed by Cisco, Salt Typhoon, the Chinese state-sponsored advanced persistent threat (APT) group, has once again targeted major U.S. telecom companies, including T-Mobile, AT&T, and Verizon. This attack utilized a combination of old vulnerabilities and stolen credentials, highlighting the ongoing sophistication of cyber espionage campaigns that can go unnoticed for years. Cisco Talos researchers have now shed light on the attack vectors and provided recommendations to safeguard against further incidents.

the Attack and Vulnerabilities

Salt Typhoon’s recent exploit against telecom networks relied on a mix of old Cisco vulnerabilities and stolen login credentials to breach infrastructure. Among the exploited vulnerabilities, CVE-2018-0171 is a known flaw, but the attack also involved newer vulnerabilities, such as CVE-2023-20198, CVE-2023-20273, and CVE-2024-20399. These vulnerabilities were used in tandem with stolen credentials, granting the threat actor persistent access to compromised networks for extended periods—up to three years in some cases. During this time, they were able to conduct various malicious activities like exfiltrating configurations, pivoting across infrastructure, and modifying network settings. While no new Cisco vulnerabilities were uncovered, the continuing abuse of these flaws emphasizes the need for consistent patching and vigilance. Cisco Talos attributed the campaign to Salt Typhoon, based on the high level of sophistication, advanced access techniques, and a multi-year timeline that is typical of state-sponsored groups.

What Undercode Says: Analyzing the Implications of Salt

Salt Typhoon’s ongoing campaign reveals troubling insights into how advanced persistent threat (APT) groups, especially those state-sponsored, continue to evolve their methods for long-term, undetected access to critical infrastructure. This attack on major telecom providers underscores a growing trend of leveraging older vulnerabilities combined with new techniques like stolen credentials to maintain a foothold within highly sensitive environments.

The use of CVE-2018-0171, a vulnerability that has been known for years, is particularly significant. It suggests that even though patches are available, organizations continue to neglect older security flaws, leaving the door open for cyber espionage actors to exploit them. While newer vulnerabilities such as CVE-2023-20198, CVE-2023-20273, and CVE-2024-20399 are receiving more attention, the fact that the APT group can exploit these older flaws points to a larger problem in patch management and cybersecurity hygiene.

Moreover, Salt Typhoon’s reliance on stolen login credentials highlights an ongoing issue in enterprise security—credential hygiene. Despite awareness of credential theft and the importance of multifactor authentication (MFA), too many companies still fail to secure the most basic aspects of their network access. This is an area where many organizations still fall short, and this attack demonstrates that even a single compromised credential can give attackers a gateway into vast networks, allowing them to operate undetected for years.

Another disturbing takeaway from this attack is the advanced level of coordination and planning involved. Cisco’s researchers noted that the long timeline of the campaign showed “a high degree of coordination, planning, and patience,” which are standard markers of state-sponsored operations. This suggests that these threat actors are not merely opportunistic but have a defined goal and sufficient resources to carry out a long-term operation. The ability to maintain persistent access to a network for years raises concerns about the strategic value of such espionage for state actors—particularly when it comes to communication and telecommunications infrastructure, which are key to national security and intelligence gathering.

The nature of this attack—spanning over years—also speaks to the growing complexity of modern cyber espionage campaigns. In the past, APT attacks were often discovered relatively quickly, but with advancements in stealth techniques and the use of long-lived vulnerabilities, attackers can remain embedded in the network, executing their objectives without detection. This means that the traditional methods of identifying and stopping cyber attacks—based on immediate breach detection—are increasingly insufficient for defending against highly sophisticated APTs.

For companies and governments to protect themselves from these types of attacks, they must adopt a more holistic approach to cybersecurity. This includes the continuous application of patches, improving credential management practices, and ensuring that sensitive infrastructure is monitored for signs of unauthorized access. Additionally, embracing a proactive security posture with threat intelligence, real-time monitoring, and automated response capabilities can help mitigate the risks posed by such well-funded and technically capable adversaries.

Finally, the Salt Typhoon case serves as a reminder of the critical importance of collaboration between private industry, cybersecurity researchers, and government agencies. By sharing threat intelligence and working together to detect and neutralize advanced persistent threats, organizations can strengthen their defenses against the growing and evolving landscape of cyber espionage. The Salt Typhoon attack is not just a wake-up call for telecom companies but for the entire cybersecurity ecosystem—underscoring the need for vigilance and resilience in the face of increasingly sophisticated adversaries.

References:

Reported By: https://www.darkreading.com/cyber-risk/cisco-salt-typhoon-exploitation-telecom
Extra Source Hub:
https://www.quora.com
Wikipedia: https://www.wikipedia.org
Undercode AI

Image Source:

OpenAI: https://craiyon.com
Undercode AI DI v2Featured Image