FBI seeks help to unmask Salt Typhoon hackers behind telecom breaches
ID: c9a46fce-7a3a-5b0a-b34a-16fd251fd10e
STIX ID: report--c9a46fce-7a3a-5b0a-b34a-16fd251fd10e
Feed Name: Bleeping Computer
U.S. authorities attribute a large, ongoing campaign by the China-linked Salt Typhoon APT against telecommunications providers globally; the group exploited unpatched Cisco IOS XE vulnerabilities (including privilege escalation and Web UI command injection), deployed a custom monitoring tool called JumbledPath, and exfiltrated call data logs and a limited number of private communications. The FBI and CISA have publicly confirmed the breaches, the Treasury’s OFAC sanctioned a Chinese firm alleged to be involved, and the U.S. State Department is offering rewards for information on the actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
