Skip to content

other

Salt Typhoon

Salt Typhoon is a Chinese state-sponsored hacking group known for long-term espionage intrusions into telecom and network infrastructure worldwide.

Current stories

build1 publisher

Elttam's two-packet exploit runs code on TACACS+ servers before anyone logs in

Elttam says a TACACS+ server flaw lets attackers run code before login with two packets and an offline crack of the protocol's weak encryption. Of the two main server codebases, Shrubbery Networks' has a fix that still has no CVE and Facebook's archived fork will get none, so the first job is finding out which daemon answers on port 49.

Publishers:news.risky.biz

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives35
Confidence40
security6 publishers

Fire Ant taught a Cisco IOS XR router to forward only log lines containing the word Health

Sygnia found the China-nexus group running packet captures, a tac_plus credential hook and two layers of log suppression on the gear that authenticates the rest of the estate, and it never established how the router was breached.

Perspective Coverage

6 publishers
Builder
Builder 33%
Operator
Operator 53%
Investor
Investor 14%

Reality

Evidence68
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence64
security3 publishers

Warner and Cruz's Salt Typhoon bill keeps telecom security voluntary for carriers

Sens. Mark Warner and Ted Cruz filed a bill giving NTIA 18 months to write voluntary telecom security practices, with an optional third-party certification. Adopting them stays each carrier's choice, nearly a year after the mandatory post-breach rules were scrapped.

Perspective Coverage

3 publishers
Builder
Builder 18%
Operator
Operator 57%
Investor
Investor 25%

Reality

Evidence72
Adoption
Insufficient
Hype gap0
Incentives30
Confidence68
security1 publisher

Salt Typhoon logged into telecom network gear with stolen credentials in all but one case Talos examined

Salt Typhoon used legitimate stolen credentials to reach Cisco devices in every telecom intrusion Cisco Talos investigated but one. It then pulled more logins from weakly encrypted router configs and captured TACACS and RADIUS keys, so credentials stored on network gear are the first exposure for defenders to close.

Reality

Evidence62
Adoption
Insufficient
Hype gap−5
Incentives55
Confidence60
security5 publishers

FamousSparrow replaced SparrowDoor with SparroWocky in a year of Latin American intrusions

ESET traced more than a year of espionage against government organizations in eight Latin American countries and territories to a modular C++ implant that hooks CreateThread so every thread it spawns looks like AnimateWindow.

Perspective Coverage

5 publishers
Builder
Builder 22%
Operator
Operator 68%
Investor
Investor 10%

Reality

Evidence70
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence68