• News/
  • https://www.bleepingcomputer.com/news/security/salt-typhoon-uses-jumbledpath-malware-to-spy-on-us-telecom-networks/

Chinese hackers use custom malware to spy on US telecom networks

BleepingComputer
·
Bill Toulas
·
Published Feb 20, 2025
·
Updated

The Chinese state-sponsored Salt Typhoon hacking group uses a custom utility called JumbledPath to stealthily monitor network traffic and potentially capture sensitive data in cyberattacks on U.S. telecommunication providers. Salt Typhoon (aka Earth Estries, GhostEmperor, and UNC2286) is a sophisticated hacking group active since at least 2019, primarily focusing on breaching government entities and telecommunications companies. Recently, the U.S. authorities have confirmed that Salt Typhoon was behind several successful breaches of telecommunication service providers in the U.S., including Verizon, AT&T, Lumen Technologies, and T-Mobile. It was later revealed that Salt Typhoon managed to tap into the private communications of some U.S. government officials and stole information related to court-authorized wiretapping requests. Last week, the Recorded Future's Insikt Group reported that Salt Typhoon targeted over 1,000 Cisco network devices, more than half from the U.S., South America, and India, between December 2024 and January 2025, Today, Cisco Talos revealed more details about the threat actor's activity when they breached major telecommunications companies in the U.S., which in some cases spanned over three years. Cisco says Salt Typhoon hackers infiltrated core networking infrastructure primarily through stolen credentials. Apart from a single case involving exploitation of the Cisco CVE-2018-0171 flaw, the cybersecurity company has seen no other flaws, known or zero-...

Read full article

Affected Software

3 affected components
Cisco Systems
Cisco Network Devices
Cisco Nexus

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the Salt Typhoon hacking group from China using custom malware to spy on US telecom networks.

2

What security implications are discussed?

The implications include the potential capture of sensitive data from US telecommunication providers by the Salt Typhoon group.

3

What malware is used by the Salt Typhoon group?

The hackers use a custom malware utility called JumbledPath.

4

What type of organizations are targeted by the Salt Typhoon hacking group?

The group targets US telecommunication providers for espionage activities.

5

What specific products from Cisco are mentioned as being affected?

The affected products include Cisco Systems, Cisco Network Devices, and Cisco Nexus.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203