logo

Weathering the storm: In the midst of a Typhoon

ID: 401291cb-51a2-525d-b247-d6d3c2f11874

STIX ID: report--401291cb-51a2-525d-b247-d6d3c2f11874

Feed Name: Cisco Talos

Threat Score
90/100

Date Published: 2025-02-20

Date Updated: 2026-04-27

Author: Cisco Talos

...
...

Cisco Talos reports on a sustained, highly sophisticated intrusion campaign by the actor dubbed Salt Typhoon targeting U.S. telecommunications core network devices. The actor used stolen legitimate credentials, living-off-the-land techniques, configuration exfiltration (often via TFTP/FTP), packet captures (including a custom Go utility called JumbledPath), and persistent shell modifications to pivot across infrastructure and maintain long-term access; the report includes IOCs, references to CVE-2018-0171 Smart Install abuse (separate activity), and detailed detection and hardening guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.