logo

Chinese hackers breached National Guard to steal network configurations

ID: 7aaf3a6e-681e-5a26-983b-64978a1c2ce4

STIX ID: report--7aaf3a6e-681e-5a26-983b-64978a1c2ce4

Feed Name: Bleeping Computer

Threat Score
92/100

Date Published: 2025-07-17

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Salt Typhoon, a Chinese state-sponsored hacking group, breached and remained undetected in a U.S. Army National Guard network from March to December 2024, exfiltrating network diagrams, configuration files, administrator credentials, and personal data; DHS warns the group has stolen 1,462 network configuration files from ~70 U.S. government and critical infrastructure entities and has used CVE exploits (including CVE-2018-0171, CVE-2023-20198, CVE-2023-20273, CVE-2024-3400), custom malware (JumblePath, GhostSpider), and identified IP addresses to facilitate intrusions and follow-on compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.