GettyImages-2138018076
– Gizem Gecim/Getty Images

In a joint advisory issued by U.S. and allied security agencies, the state-sponsored Salt Typhoon group was revealed to be actively targeting critical networks through a wider attack area than previously reported.

The modus operandi primarily exploits known flaws on backbone routers, provider edge (PE), and customer edge (CE) devices. The vulnerabilities affect software from Palo Alto Networks, Cisco, and Ivanti, with no zero-day vulnerabilities reported.

Affiliated with the People’s Republic of China (PRC), Salt Typhoon was blamed for what was dubbed the worst telecom hack in U.S. history last year, which saw attacks on T-Mobile, AT&T, Verizon, and Lumen Technologies, among others.

Aside from telecoms, the group also targets government, transportation, and military infrastructures.

Three Chinese companies, meanwhile, have been suspected of supplying cyber tools to China's Ministry of State Security and the People's Liberation Army (PLA).

Sichuan Juxinhe Network Technology Co., Ltd was first sanctioned in January 2025 by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), accused of direct involvement in the U.S. telecommunications mega-hack.

According to its website, the company is an end-to-end ICT infrastructure vendor that provides data center switches, Ethernet solutions, and routers.

The company’s Sichuan Zhixin Ruijie subsidiary was also fingered in the security report, alongside Beijing Huanyu Tianqiong Information Technology Co.

Bug and backbone breakdown

According to the advisory, Salt Typhoon targets publicly disclosed vulnerabilities affecting Cisco IOS XE Web UI (CVE‑2023‑20198), Cisco Smart Install (CVE‑2018‑0171), Ivanti Connect Secure/Policy Secure, and Palo Alto GlobalProtect Gateway (CVE‑2024‑3400). These flaws range from remote code execution (RCE) to authentication bypass and privilege escalation.

After initial access, the group employs various techniques, such as configurations to access control lists on routers and firewalls.

Generic routing encapsulation (GRE) and internet protocol security (IPSec) tunneling then send data securely across networks, allowing hidden communications between infected devices and the attackers’ control servers.

Attacks also make use of Stowaway multi-hop relays, which pass traffic through several devices to hide the origin of the attack, obfuscating detection.

In addition, on-box container deployment by the group runs streamlined, containerized malware directly on network devices, giving attackers a permanent footing and the ability to deploy custom scripts or tools without relying on external endpoints.

To gather data, the attackers exploit authentication systems such as terminal access controller access-control plus (TACACS+) and remote authentication dial-in user service (RADIUS), alongside Packet Capture (PCAP) network traffic.

“Actors collected PCAPs using native tooling on the compromised system, with the primary objective likely being to capture TACACS+ traffic over TCP port 49. TACACS+ packet bodies can be decrypted if the encryption key is known,” according to the report.

Exfiltration of data is executed via encrypted tunnels and misused peering configurations, with data funneled through network address translation (NAT) pools or proxy clusters to evade detection.

Salt Typhoon attack area

According to the report, further concern about the subterfuge is the potential fallout across the wider network.

“Based on analysis, the APT actors hold interest in making configuration and routing changes to the devices after compromising the routers,” the security researchers wrote.

“While some actions are specific to Cisco devices, the actors are capable of targeting devices from other vendors and could utilize similar functionality. The APT actors perform several of the modifications or techniques below to facilitate follow-on actions.”

The gravitas of the report is highlighted by the co-signing of multiple agencies. On the U.S. side these include the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Department of Defense Cyber Crime Center (DC3), and the FBI.

The UK's National Cyber Security Centre also shared the warning, alongside government agencies from Australasia, APAC, and Europe.

The security advisory comes hot on the heels of other state-sponsored threats in the network space, including China-affiliated attacks on VMware and F5 software, alongside a compromise of more than 1,000 networking devices across the U.S. and Southeast Asia.

In August, it was also revealed that a historical Cisco bug is being exploited by a Russian espionage group, with the FBI issuing an urgent security warning.