
Chinese 'Salt Typhoon' Group Compromises Global Telecom Hubs in Massive Intelligence Harvesting Operation
A persistent espionage campaign by Chinese actor Salt Typhoon has successfully breached the core infrastructure of multiple international telecommunications providers, targeting lawful intercept systems.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2024-3400
- Source:
- Microsoft MSTIC
- Read Time:
- 5 min
Executive Summary
Encrygma Intelligence has identified a massive, ongoing cyber espionage campaign conducted by the Chinese-affiliated threat actor known as Salt Typhoon (also tracked as Ghost Emperor or Famous Sparrow). Over the past 48 hours, new forensic evidence from major telecommunications hubs in Europe and Southeast Asia reveals that the group has transitioned from initial access to deep-layer persistence within core routing infrastructure. The primary objective appears to be the systematic exfiltration of high-value metadata, geolocation logs, and the compromise of 'lawful interception' systems used by state security services.
Threat Analysis
Salt Typhoon is exhibiting a level of technical sophistication that distinguishes this campaign from typical data theft. The group is not merely stealing data but is actively 'living' within the ISP (Internet Service Provider) backbone. By targeting the virtualization layers and software-defined networking (SDN) controllers of telecom giants, the actors have gained the ability to mirror traffic from specific, high-profile targets—including diplomatic missions, defense contractors, and government officials—without triggering traditional endpoint detection systems.
Technical Details
The campaign utilizes a multi-stage infection chain that begins with the exploitation of zero-day vulnerabilities in edge gateway appliances (notably CVE-2024-3400 and similar vulnerabilities in high-capacity firewalls). Once inside, Salt Typhoon deploys a custom, modular backdoor known as 'NanoSlate', which operates entirely in memory to evade disk-based scanning.
Key technical milestones observed include:
- Kernel-Level Persistence: The use of a modified Rootkit designed for Cisco and Juniper routing OS environments, allowing the actor to manipulate BGP (Border Gateway Protocol) tables and divert traffic.
- Encrypted Exfiltration: Stolen data is tunneled through legitimate cloud services (GitHub and Microsoft Azure) using custom obfuscation scripts that mimic standard API traffic.
- Credential Harvesting: Aggressive use of 'Pass-the-Ticket' attacks against administrative accounts to move laterally from the IT network into the specialized Operational Technology (OT) networks governing telecom switching.
Attribution Assessment
With high confidence, Encrygma attributes this activity to the People's Republic of China (PRC). The tradecraft—specifically the focus on telecommunications for intelligence gathering, the use of custom 'Typhoon-class' malware, and the alignment with Beijing's strategic interests in the South China Sea and European trade corridors—points directly to a state-sponsored mission. The infrastructure used for Command and Control (C2) shares significant overlaps with previous campaigns attributed to the PRC Ministry of State Security (MSS).
Implications
The compromise of lawful interception systems is particularly grave. It allows a foreign adversary to see exactly who local law enforcement and intelligence agencies are monitoring, effectively 'spying on the spies.' This capability grants the PRC the power to identify undercover assets, anticipate diplomatic moves, and compromise the integrity of national security investigations across multiple continents.
Recommendations
- Infrastructure Isolation: Immediately isolate and audit all edge-facing network management interfaces and apply out-of-band management protocols.
- Zero-Trust Implementation: Move toward a strict Zero-Trust Architecture for administrative access to core switching and routing layers.
- BGP Monitoring: Implement real-time BGP route monitoring to detect unauthorized prefix hijacking or traffic redirection.
- Credential Reset: Conduct a mandatory, global reset of all service accounts and privileged credentials within the telecommunications environment.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
