RedMike (Salt Typhoon) Exploits Vulnerable Cisco Devices of Global Telecommunications Providers
ID: e3fda884-c671-5bdb-9e5f-3971d9e225cc
STIX ID: report--e3fda884-c671-5bdb-9e5f-3971d9e225cc
Feed Name: Recorded Future Blog
Recorded Future’s Insikt Group attributes a December 2024–January 2025 campaign to RedMike (Microsoft: Salt Typhoon) that attempted to exploit over 1,000 internet-facing Cisco IOS XE devices worldwide using CVE-2023-20198 and CVE-2023-20273 to create privileged accounts and escalate to root, then add GRE tunnels for persistent covert access; primary targets included telecommunications providers and select universities, with confirmed compromises and documented reconnaissance activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
