logo
China's Salt Typhoon Spies Are Still Hacking Telecoms—Now by Exploiting Cisco Routers

China's Salt Typhoon Spies Are Still Hacking Telecoms—Now by Exploiting Cisco Routers

WIRED13-02-2025
Feb 13, 2025 12:00 AM Despite high-profile attention and even US sanctions, the group hasn't stopped or even slowed its operation, including the breach of two more US telecoms. A server room at the Cisco Systems Poland headquarters in Krakow, Poland. Photograph:When the Chinese hacker group known as Salt Typhoon was revealed last fall to have deeply penetrated major US telecommunications companies—ultimately breaching no fewer than nine of the phone carriers and accessing Americans' texts and calls in real time—that hacking campaign was treated as a four-alarm fire by the US government. Yet even after those hackers' high-profile exposure, they've continued their spree of breaking into telecom networks worldwide, including more in the US.
Researchers at cybersecurity firm Recorded Future on Wednesday night revealed in a report that they've seen Salt Typhoon breach five telecoms and internet service providers around the world, as well as more than a dozen universities from Utah to Vietnam, all between December and January. The telecoms include one US internet service provider and telecom firm and another US-based subsidiary of a UK telecom, according to the company's analysts, though they declined to name those victims to WIRED.
'They're super active, and they continue to be super active,' says Levi Gundert, who leads Recorded Future's research team known as Insikt Group. 'I think there's just a general under-appreciation for how aggressive they are being in turning telecommunications networks into Swiss cheese.'
To carry out this latest campaign of intrusions, Salt Typhoon—which Recorded Future tracks under its own name, RedMike, rather than the Typhoon handle created by Microsoft—has targeted the internet-exposed web interfaces of Cisco's IOS software, which runs on the networking giant's routers and switches. The hackers exploited two different vulnerabilities in those devices' code, one of which grants initial access, and another that provides root privileges, giving the hackers full control of an often powerful piece of equipment with access to a victim's network.
'Any time you're embedded in communication networks on infrastructure like routers, you have the keys to the kingdom in what you're able to access and observe and exfiltrate,' Gundert says.
Recorded Future found more than 12,000 Cisco devices whose web interfaces were exposed online, and says that the hackers targeted more than a thousand of those devices installed in networks worldwide. Of those, they appear to have focused on a smaller subset of telecoms and university networks whose Cisco devices they successfully exploited. For those selected targets, Salt Typhoon configured the hacked Cisco devices to connect to the hackers' own command-and-control servers via generic routing encapsulation, or GRE tunnels—a protocol used to set up private communications channels—then used those connections to maintain their access and steal data.
When WIRED reached out to Cisco for comment, the company pointed to a security advisory it published about vulnerabilities in the web interface of its IOS software in 2023. 'We continue to strongly urge customers to follow recommendations outlined in the advisory and upgrade to the available fixed software release,' a spokesperson wrote in a statement.
Hacking network appliances as entry points to target victims—often by exploiting known vulnerabilities that device owners have failed to patch—has become standard operating procedure for Salt Typhoon and other Chinese hacking groups. That's in part because those network devices lack many of the security controls and monitoring software that's been extended to more traditional computing devices like servers and PCs. Recorded Future notes in its report that sophisticated Chinese espionage teams have targeted those vulnerable network appliances as a primary intrusion technique for at least five years.
That Salt Typhoon continues to carry out business as usual is nonetheless notable, Recorded Future's analysts say. The group's activities have been exposed in the media, in government reports and announcements issued by the FCC, CISA, and the White House, even in sanctions issued by the US Treasury. But that hasn't caused the hackers to change course. On January 17, Treasury sanctioned Sichuan Juxinhe Network Technology, a cybersecurity firm allegedly linked to Salt Typhoon's operations. And yet, Gundert says, Recorded Future hasn't seen any cessation or slowdown of the hackers' activities even since that date.
'That's the disappointing part about this,' says Gundert. 'Even with all the attention, we haven't observed any real change in the volume or velocity of attacks, even in the same target demographic of telecommunications.'
After Salt Typhoon's hacking campaign targeting US telecom networks came to light last fall, then FBI director Christopher Wray described the phone company breaches as China's 'most significant cyber-espionage campaign in history.' The intrusions, which in some cases exploited the wiretap mechanisms built into telecoms for law enforcement use, prompted CISA and FBI officials to go so far as to recommend that Americans use end-to-end encrypted communication apps like Signal and WhatsApp to avoid leaving their texts and calls vulnerable to China's real-time spying.
In this latest rash of intrusions, Recorded Future says it's seen the Chinese hackers break into not only the US internet service provider and telecommunications firm and a US affiliate of a UK telecom, but also telecoms in South Africa and Thailand and an internet service provider in Italy, though it declined to name any of those victims. It's also seen the group target a broader range of universities around the world for apparent espionage, including in Argentina, Bangladesh, Indonesia, Malaysia, Mexico, Netherland, Thailand, Vietnam, and the US—including the University of California, California State, Utah Tech, and Loyola University.
Recorded Future says it was able to gain visibility into those intrusions by identifying command-and-control infrastructure used by Salt Typhoon, though it didn't further explain its methodology. The company's analysts note that there may well be other parts of the group's hacking campaign—and other victims—that it hasn't discovered.
'They've only gotten more bold,' says Jon Condra, another Recorded Future analyst. 'I strongly suspect it's much larger than what we've seen.'
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

White House Launches TikTok Account
White House Launches TikTok Account

Time​ Magazine

time24 minutes ago

  • Time​ Magazine

White House Launches TikTok Account

The White House has created an official TikTok account just weeks before the deadline that President Donald Trump extended for the Chinese-owned app to be sold to a non-Chinese buyer or face a ban in the U.S. The account, @whitehouse, was launched Tuesday evening and gained more than 80,000 followers as of early Wednesday. Trump's campaign used a TikTok account, @realdonaldtrump, which now has more than 15 million followers, before the presidential election last year. Trump's aides said last year that his TikTok was 'the most successful launch in political history' and credited it with being his 'secret sauce.' 'I am your voice,' Trump declares in the first video posted to the White House account, featuring footage of him spliced together and a caption reading, 'America we are BACK! What's up TikTok?' 'The Trump administration is committed to communicating the historic successes President Trump has delivered to the American people with as many audiences and platforms as possible,' White House Press Secretary Karoline Leavitt told Reuters on Tuesday. 'President Trump's message dominated TikTok during his presidential campaign, and we're excited to build upon those successes and communicate in a way no other administration has before.' Federal employees are not allowed to download the app on work devices with limited exceptions, per a law passed during the Biden Administration. Trump's TikTok evolution The Trump Administration has sought to negotiate a deal for the sale of TikTok, which is owned by Chinese company ByteDance, to a non-Chinese buyer before Sept. 17. The app was initially banned in the U.S. after President Joe Biden signed a bipartisan law last year requiring ByteDance to divest from the app over national security concerns. TikTok has argued that a U.S. ban violates the First Amendment, though the Supreme Court upheld the ban. On the evening of Jan. 18, the app was removed from U.S. app stores and users were met with a message reading, 'Sorry, TikTok isn't available right now. A law banning TikTok has been enacted in the U.S. Unfortunately that means you can't use TikTok for now.' Hours later, the app was live again as Trump announced that he extended the deadline for ByteDance to sell. A message on the app read: 'Thanks for your patience and support. As a result of President Trump's efforts, TikTok is back in the U.S.!' TikTok CEO Shou Zi Chew, who attended Trump's inauguration, praised Trump for the extension in a video message. Read More: Why Trump Flipped on TikTok The President has since extended the deadline several more times, although a sale before the current September deadline looks uncertain. Trump said in June that a deal with 'a group of very wealthy people' was close, contingent on approval from Beijing. Trump has also acknowledged that his tariffs on China may have made a sale harder. Trump himself had called TikTok a national security threat during his first presidential term, and the ban on the app was driven by a bipartisan push. 'The spread in the United States of mobile applications developed and owned by companies in [China] continues to threaten the national security, foreign policy, and economy of the United States,' an executive order signed by Trump in 2020 reads. 'The United States must take aggressive action against the owners of TikTok to protect our national security.'

Medium-Duty Electric Trucks Gain Momentum Amid Stricter Emission Regulations
Medium-Duty Electric Trucks Gain Momentum Amid Stricter Emission Regulations

Yahoo

timean hour ago

  • Yahoo

Medium-Duty Electric Trucks Gain Momentum Amid Stricter Emission Regulations

Growth is driven by the rising adoption of medium-duty electric trucks, bolstered by stringent emission regulations and urban delivery needs. The U.S. market is poised as a leader, supported by federal incentives and robust infrastructure investments. Electric Truck Market Dublin, Aug. 20, 2025 (GLOBE NEWSWIRE) -- The "Electric Truck Market by Propulsion (BEV, PHEV, FCEV), Type (Light-duty Trucks, Medium-duty Trucks, Heavy-duty Trucks), Range, Battery Type, Battery Capacity, Level of Automation, End User, Payload Capacity, and Region - Global Forecast to 2032" has been added to electric truck market is anticipated to grow at a CAGR of 29.5%, reaching USD 32.13 billion by 2032 from USD 5.24 billion in 2025. The increase in medium-duty electric trucks is driven by stringent emission regulations and operational benefits for urban and regional delivery. Cities globally are implementing stricter vehicle emissions limits, bolstered by the rise of medium-duty trucks used for last-mile delivery. Electric trucks between Class 4 and Class 6 offer a zero-emission solution, meeting regulatory goals and supporting low-emission zone initiatives. Reduced noise levels make these trucks ideal for off-peak deliveries in urban locations. Companies like Ford and BYD have introduced medium-duty electric models designed for urban freight and field services. These trucks typically cover 150 to 200 miles per charge, sufficient for daily operations, and offer a lower total cost of ownership. Fleet operators are increasingly adopting these vehicles as sustainable and strategic assets, aligning with corporate ESG goals. The market is dominated by key players like BYD, AB Volvo, Ford Motor Company, Daimler Truck AG, and Dongfeng. The report segments the market based on propulsion, type, battery type, end users, range, payload capacity, and region, focusing on BEV, PHEV, and FCEV technology. Long-range Electric Trucks to See Fastest Growth Trucks with ranges above 200 miles will experience significant growth as fleet operators demand long-range solutions for regional logistics. This growth is supported by advancements in battery technology, with models like Tesla Semi and Freightliner eCascadia demonstrating extended capabilities. Long-range electric trucks are increasingly used in intercity transportation, contributing to productivity and cost efficiency. The rapid segment growth is bolstered by investments in high-capacity charging infrastructures, especially in the US, Canada, and Europe, where public and private initiatives are accelerating infrastructure deployment. Major logistics providers like PepsiCo and DHL are already exploring long-range electric trucks for operations. Stricter carbon regulations and incentives for zero-emission vehicles create favorable conditions for fleet transitions, making long-range electric trucks a valuable addition. As battery prices decline and range anxiety decreases, these trucks provide a compelling solution for decarbonizing operations without sacrificing logistical scope. The US Leads North American Electric Truck Market The US is poised to dominate the North American market, driven by federal regulations, state mandates, and electrification investments. The EPA and DOT have set stringent targets for vehicle emissions, accelerating the shift to electric alternatives, complemented by state policies like California's Advanced Clean Trucks rule. The Inflation Reduction Act further incentivizes commercial EV adoption, making it cost-effective for operators to transition. Leading companies such as Tesla, Ford, Rivian, and Freightliner are responding by increasing electric truck production to meet rising demand. The US market benefits from expanding charging infrastructure and significant participation from large logistics companies, with giants like Amazon and Walmart committing to electrifying their fleets. Key Attributes Report Attribute Details No. of Pages 301 Forecast Period 2025-2032 Estimated Market Value (USD) in 2025 $5.24 Billion Forecasted Market Value (USD) by 2032 $32.13 Billion Compound Annual Growth Rate 29.5% Regions Covered Global Key Topics CoveredMarket Dynamics Drivers Declining Battery Costs Government Initiatives Promoting Electric Commercial Vehicle Sales Increasing Range of Electric Trucks Growing Demand for Electric Trucks in Logistics and Other Industrial Sectors Restraints High Initial Investment for Production Lack of EV Charging Infrastructure Extended Charging Duration Opportunities Ongoing Development of Self-Driving Truck Technology Innovations in Fuel Cell Technology Challenges Limited Availability of Lithium for EV Batteries Inadequate Standardization of EV Charging Infrastructure Case Studies Battery-Electric Trucks Enhance User Experience in Norway Fortescue Employs Battery-Electric Trucks for Mining Operations Ruan Adopts Electric Terminal Trucks for Logistics Operations Company Profiles AB Volvo Daimler Truck AG Ford Motor Company Dongfeng Motor Corporation Rivian BYD Company Ltd. Tesla, Inc. Scania Paccar Inc. Foton International VDL Groep Workhorse Group Tata Motors Limited Ashok Leyland Isuzu Motors Ltd. Irizar Group Iveco S.p.A Bollinger Motors Xos Trucks, Inc. Man SE Kaiyun Motors Zhejiang Geely New Energy Commercial Vehicle Group Co. Ltd. Orange EV Hino Motors, Ltd. For more information about this report visit About is the world's leading source for international market research reports and market data. We provide you with the latest data on international and regional markets, key industries, the top companies, new products and the latest trends. Attachment Electric Truck Market CONTACT: CONTACT: Laura Wood,Senior Press Manager press@ For E.S.T Office Hours Call 1-917-300-0470 For U.S./ CAN Toll Free Call 1-800-526-8630 For GMT Office Hours Call +353-1-416-8900Sign in to access your portfolio

Trending tickers: Nvidia, Palantir, Oracle, Strategy and Convatec
Trending tickers: Nvidia, Palantir, Oracle, Strategy and Convatec

Yahoo

timean hour ago

  • Yahoo

Trending tickers: Nvidia, Palantir, Oracle, Strategy and Convatec

Nvidia (NVDA) Tech stocks sold off on Tuesday, with chipmaker Nvidia (NVDA) closing the session 3.5% in the red, and hovered just below the flatline in pre-market trading on Wednesday. The US tech-focused Nasdaq (^IXIC) ended Tuesday's session down around 1.5%, and futures linked to the index (NQ=F) were down 0.3% at the time of writing. Read more: Stocks slip as UK inflation jumps to highest level since January last year The fall in tech stocks came after a report by the Massachusetts Institute of Technology's Nanda initiative said that "95% of organisations are getting zero return" from their investments in generative artificial intelligence (AI). The sell-off also followed a report by The Verge on Friday which said OpenAI CEO Sam Altman had pointed to an AI bubble. Palantir (PLTR) Data software platform provider Palantir (PLTR) slid more than 9% on Tuesday, and was down a further 1.4% in pre-market trading on Wednesday. The fall on Tuesday marked a fifth straight losing session for Palantir shares. However, the stock is still up nearly 109% year-to-date, having risen more than 150% from its April low thanks to its second quarter earnings report, which saw the company's revenue top $1bn in a single quarter for the first time. Stocks: Create your watchlist and portfolio Steve Clayton, head of equity funds at Hargreaves Lansdown, said the fall in Palantir shares came as "investors questioned whether a valuation of over $400bn could be justified by a business which last year generated less than $3bn of revenues". The stock also came under pressure after a bearish report by short seller Citron Research published on Monday predicted a price target of $40. The firm's founder, Andrew Left, called the target "generous." Oracle (ORCL) Cloud technology company Oracle (ORCL) was another company in the sector that fell on Tuesday, sliding 5.8% and lingering just below the flatline in pre-market trading on Wednesday morning. It followed a Bloomberg report on Monday which said Oracle's longtime chief security officer Mary Ann Davidson was leaving the company as part of a recent reorganisation. A spokesperson for Oracle had not responded to Yahoo Finance UK's request for comment at the time of writing. Strategy (MSTR) Cryptocurrency-related stocks fell on Tuesday, as the price of bitcoin (BTC-USD) declined after hitting a fresh high last week. Bitcoin hit a record $124,000 last week, but has since fallen back, dipping 3% over the past five days. Read more: UK inflation rises to 18-month high in July, driven by higher air fares This has weighed on crypto-related stocks, including software company Strategy (MSTR), which is one of the largest corporate holders of bitcoin. Strategy shares tumbled more than 7% on Tuesday, though the stock was trading 1.3% in the green in pre-market trading on Wednesday. Convatec (CTEC.L) On the London market, Convatec (CTEC.L) was the biggest riser on the FTSE 100 (^FTSE) on Wednesday morning, surging more than 7%. The rise in shares came after the medical products and technology company announced that it was commencing a $300m share buyback programme. Convatec said that the programme would start immediately and would run until 31 December, adding that it could be extended. Read more: How rising inflation will affect your state pension Should CEO pay be capped? Have your say How to find the weak link in your financesError in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store