logo

China’s Salt Typhoon hackers targeting Cisco devices used by telcos, universities

ID: b26b7f10-9d0e-5a7d-b590-973e6ba0f637

STIX ID: report--b26b7f10-9d0e-5a7d-b590-973e6ba0f637

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-02-13

Date Updated: 2026-05-01

...
...

Recorded Future’s Insikt Group detailed a Salt Typhoon campaign (attributed to Chinese state-linked actors) that in Dec–Jan scanned and attempted to compromise over 1,000 Cisco devices associated with telecommunications providers worldwide, successfully compromising at least seven devices across the U.S., South Africa, Italy and Thailand. The attackers exploited CVE-2023-20198 and CVE-2023-20273 to gain and escalate access, reconfigured devices for persistence, and allegedly accessed call records of high-profile political figures; U.S. agencies and the Treasury have taken notice and imposed sanctions related to the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.