logo

FBI seeks help to unmask Salt Typhoon hackers behind telecom breaches

ID: c9a46fce-7a3a-5b0a-b34a-16fd251fd10e

STIX ID: report--c9a46fce-7a3a-5b0a-b34a-16fd251fd10e

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-04-25

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

U.S. authorities attribute a large, ongoing campaign by the China-linked Salt Typhoon APT against telecommunications providers globally; the group exploited unpatched Cisco IOS XE vulnerabilities (including privilege escalation and Web UI command injection), deployed a custom monitoring tool called JumbledPath, and exfiltrated call data logs and a limited number of private communications. The FBI and CISA have publicly confirmed the breaches, the Treasury’s OFAC sanctioned a Chinese firm alleged to be involved, and the U.S. State Department is offering rewards for information on the actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.