Skip to content

Security1 publisher2 min readPublished

Salt Typhoon logged into telecom network gear with stolen credentials in all but one case Talos examined

Salt Typhoon used legitimate stolen credentials to reach Cisco devices in every telecom intrusion Cisco Talos investigated but one. It then pulled more logins from weakly encrypted router configs and captured TACACS and RADIUS keys, so credentials stored on network gear are the first exposure for defenders to close.

The Watch · Security desk

Illustration accompanying Salt Typhoon logged into telecom network gear with stolen credentials in all but one case Talos examined

What happened

  • Intrusions by the actor Salt Typhoon at several major U.S. telecommunications companies were first reported in late 2024 and later confirmed by the U.S. government.
  • Cisco Talos found that initial access to Cisco devices came from legitimate victim login credentials in every incident it has investigated, bar one.
  • In the one exception, Talos found evidence suggesting the actor likely abused CVE-2018-0171, a Smart Install remote code execution flaw in Cisco IOS and IOS XE.
  • The actor held access across multiple vendors' equipment for extended periods, and in one environment for more than three years.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Patch compliance alone would not have stopped most of these entries, because a fully patched device still accepts a valid administrator login.
  • exposure Router configs holding weak password types or SNMP read/write strings let one login become several, so every stored or transferred copy of a config file is a credential store.
  • decision Monitoring confined to one vendor's devices sees only part of an intrusion path that Talos says crossed several vendors' equipment and lasted years in one network.

Talos does not know where the first logins came from. It wrote that "it is unknown at this time exactly how the initial credentials in all cases were obtained by the threat actor" [8]. Talos documented the steps after that first login in detail.

The actor pulled device configurations, often over TFTP or FTP [11]. Those files often held SNMP read/write community strings and local accounts stored with weak password types. Talos says the weak type lets an attacker decrypt the password offline trivially [11]. The actor went after those accounts on purpose, collecting configs so it could decipher them [9]. Configs also listed named interfaces. Talos says those can show an attacker the upstream and downstream segments to scout and move into next [12].

The actor also captured SNMP, TACACS and RADIUS traffic, including the secret keys that network devices share with TACACS and RADIUS servers [10]. Talos assesses the goal was "almost certainly" more credentials for follow-on use [10]. The actor jumped from machine to machine through compromised infrastructure, staying inside trusted segments where its connections might otherwise be blocked [14]. Talos calls living-off-the-land techniques on network devices a hallmark of the campaign [13]. It found no new Cisco vulnerabilities [5].

Public reports have also tied Salt Typhoon to CVE-2023-20198 and CVE-2023-20273 in the IOS XE Web UI, and to CVE-2024-20399, an NX-OS CLI command injection [17]. Talos wrote that "we have not identified any evidence to confirm these claims" [6]. Of the four Cisco CVEs Talos listed, it found likely abuse of one [1]. It still calls patching all four imperative. Fixes exist, and attackers regularly exploit these flaws with public tooling [7]. Cisco last updated the four advisories between December 2022 and September 2024 [16][17].

The evidence puts credential hygiene on network devices first, with patching kept as the baseline Talos already recommends. Resetting a password does not cover everything the actor took. If an operator rotates a stolen admin login but leaves the SNMP community strings and the TACACS and RADIUS shared keys unchanged, the actor still holds the secrets Talos says it collected [10][11]. Telecoms are the primary victims, but Talos says its guidance applies to all infrastructure defenders [15].

What to watch

  • A finding on how Salt Typhoon got its initial credentials; Talos says that is still unknown, and the answer decides where the first control belongs.
  • Confirmed evidence of Salt Typhoon exploiting CVE-2023-20198, CVE-2023-20273 or CVE-2024-20399; Talos has found none, and a confirmation would give patch gaps more weight.
  • Findings from the non-Cisco vendors whose equipment Talos says the actor persisted on.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories