News Room
16
Share
Chinese 'Salt Typhoon' Group Compromises Global Telecom Hubs in Massive Intelligence Harvesting Operation
criticalCyber Espionage

Chinese 'Salt Typhoon' Group Compromises Global Telecom Hubs in Massive Intelligence Harvesting Operation

A persistent espionage campaign by Chinese actor Salt Typhoon has successfully breached the core infrastructure of multiple international telecommunications providers, targeting lawful intercept systems.

20 July 2026Last updated 20 August 20265 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2024-3400
Source:
Microsoft MSTIC
Read Time:
5 min

Executive Summary

Encrygma Intelligence has identified a massive, ongoing cyber espionage campaign conducted by the Chinese-affiliated threat actor known as Salt Typhoon (also tracked as Ghost Emperor or Famous Sparrow). Over the past 48 hours, new forensic evidence from major telecommunications hubs in Europe and Southeast Asia reveals that the group has transitioned from initial access to deep-layer persistence within core routing infrastructure. The primary objective appears to be the systematic exfiltration of high-value metadata, geolocation logs, and the compromise of 'lawful interception' systems used by state security services.

Threat Analysis

Salt Typhoon is exhibiting a level of technical sophistication that distinguishes this campaign from typical data theft. The group is not merely stealing data but is actively 'living' within the ISP (Internet Service Provider) backbone. By targeting the virtualization layers and software-defined networking (SDN) controllers of telecom giants, the actors have gained the ability to mirror traffic from specific, high-profile targets—including diplomatic missions, defense contractors, and government officials—without triggering traditional endpoint detection systems.

Technical Details

The campaign utilizes a multi-stage infection chain that begins with the exploitation of zero-day vulnerabilities in edge gateway appliances (notably CVE-2024-3400 and similar vulnerabilities in high-capacity firewalls). Once inside, Salt Typhoon deploys a custom, modular backdoor known as 'NanoSlate', which operates entirely in memory to evade disk-based scanning.

Key technical milestones observed include:

  • Kernel-Level Persistence: The use of a modified Rootkit designed for Cisco and Juniper routing OS environments, allowing the actor to manipulate BGP (Border Gateway Protocol) tables and divert traffic.
  • Encrypted Exfiltration: Stolen data is tunneled through legitimate cloud services (GitHub and Microsoft Azure) using custom obfuscation scripts that mimic standard API traffic.
  • Credential Harvesting: Aggressive use of 'Pass-the-Ticket' attacks against administrative accounts to move laterally from the IT network into the specialized Operational Technology (OT) networks governing telecom switching.

Attribution Assessment

With high confidence, Encrygma attributes this activity to the People's Republic of China (PRC). The tradecraft—specifically the focus on telecommunications for intelligence gathering, the use of custom 'Typhoon-class' malware, and the alignment with Beijing's strategic interests in the South China Sea and European trade corridors—points directly to a state-sponsored mission. The infrastructure used for Command and Control (C2) shares significant overlaps with previous campaigns attributed to the PRC Ministry of State Security (MSS).

Implications

The compromise of lawful interception systems is particularly grave. It allows a foreign adversary to see exactly who local law enforcement and intelligence agencies are monitoring, effectively 'spying on the spies.' This capability grants the PRC the power to identify undercover assets, anticipate diplomatic moves, and compromise the integrity of national security investigations across multiple continents.

Recommendations

  1. Infrastructure Isolation: Immediately isolate and audit all edge-facing network management interfaces and apply out-of-band management protocols.
  2. Zero-Trust Implementation: Move toward a strict Zero-Trust Architecture for administrative access to core switching and routing layers.
  3. BGP Monitoring: Implement real-time BGP route monitoring to detect unauthorized prefix hijacking or traffic redirection.
  4. Credential Reset: Conduct a mandatory, global reset of all service accounts and privileged credentials within the telecommunications environment.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo