• News/
  • https://www.darkreading.com/cyberattacks-data-breaches/salt-typhoon-exploits-cisco-devices-telco-infrastructure

Salt Typhoon Exploits Cisco Devices in Telco Infrastructure

Dark Reading
·
Nate Nelson
·
Published Feb 14, 2025
·
Updated

The Chinese advanced persistent threat (APT) known as Salt Typhoon has targeted more than a thousand Cisco devices located within the infrastructures of telecommunications companies, internet service providers (ISPs), and universities. Salt Typhoon (aka RedMike, Earth Estries, FamousSparrow, GhostEmperor, and UNC2286) first made its name last fall, with explosive reports about its targeting major US telecommunications providers like T-Mobile, AT&T, and Verizon. In the process, it managed to eavesdrop on US law enforcement wiretaps, and even the Democratic and Republican presidential campaigns. Apparently, all that new media attention did little to slow it down. According to Recorded Future's Insikt Group, Salt Typhoon — which Insikt tracks as "RedMike" — attacked communications providers and research universities worldwide on six occasions in December and January. The group exploited old bugs in Cisco network devices to infiltrate its targets, and this may not actually be the first time it tried this tactic. In a statement to Dark Reading, a Cisco spokesperson wrote that "We are aware of new reports that claim Salt Typhoon threat actors are exploiting two known vulnerabilities in Cisco devices relating to IOS XE. To date, we have not been able to validate these claims but continue to review available data." They added that "In 2023, we issued a security advisory disclosing these vulnerabilities along with guidance for customers to urgently apply the available software fix. We...

Read full article

Affected Software

2 affected components
Cisco IOS XE
Cisco Network Devices

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the targeting of Cisco devices by the Chinese APT group known as Salt Typhoon.

2

What security implications are discussed in the article?

The article highlights the risks associated with advanced persistent threats exploiting vulnerabilities in telecommunications infrastructure.

3

What products or software are affected by Salt Typhoon?

The affected products include Cisco IOS XE and various Cisco network devices.

4

Who are the targets of the Salt Typhoon cyberattacks?

The targeted entities include telecommunications companies, internet service providers, and universities.

5

What is the nature of the threat posed by Salt Typhoon?

Salt Typhoon represents a significant cybersecurity threat due to its advanced persistent threat techniques and targeting of critical infrastructure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203