The Chinese state-sponsored Salt Typhoon hacking group uses a custom utility called JumbledPath to stealthily monitor network traffic and potentially capture sensitive data in cyberattacks on U.S. telecommunication providers. Salt Typhoon (aka Earth Estries, GhostEmperor, and UNC2286) is a sophisticated hacking group active since at least 2019, primarily focusing on breaching government entities and telecommunications companies. Recently, the U.S. authorities have confirmed that Salt Typhoon was behind several successful breaches of telecommunication service providers in the U.S., including Verizon, AT&T, Lumen Technologies, and T-Mobile. It was later revealed that Salt Typhoon managed to tap into the private communications of some U.S. government officials and stole information related to court-authorized wiretapping requests. Last week, the Recorded Future's Insikt Group reported that Salt Typhoon targeted over 1,000 Cisco network devices, more than half from the U.S., South America, and India, between December 2024 and January 2025, Today, Cisco Talos revealed more details about the threat actor's activity when they breached major telecommunications companies in the U.S., which in some cases spanned over three years. Cisco says Salt Typhoon hackers infiltrated core networking infrastructure primarily through stolen credentials. Apart from a single case involving exploitation of the Cisco CVE-2018-0171 flaw, the cybersecurity company has seen no other flaws, known or zero-...
Chinese hackers use custom malware to spy on US telecom networks
BleepingComputer
·Bill Toulas
·Published Feb 20, 2025
·Updated
Affected Software
3 affected components
Cisco Systems
Cisco Network Devices
Cisco Nexus
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the Salt Typhoon hacking group from China using custom malware to spy on US telecom networks.
2
What security implications are discussed?
The implications include the potential capture of sensitive data from US telecommunication providers by the Salt Typhoon group.
3
What malware is used by the Salt Typhoon group?
The hackers use a custom malware utility called JumbledPath.
4
What type of organizations are targeted by the Salt Typhoon hacking group?
The group targets US telecommunication providers for espionage activities.
5
What specific products from Cisco are mentioned as being affected?
The affected products include Cisco Systems, Cisco Network Devices, and Cisco Nexus.