
Salt Typhoon Breach Scales: New Evidence of Persistent Access to Lawful Intercept Systems in EU and US Backbones
Recent forensics reveal that the Chinese-linked actor Salt Typhoon has expanded its exploitation of lawful intercept systems, compromising major European and US telecommunications providers via legacy routing vulnerabilities.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- North America and Europe
- Confidence:
- High Confidence
- Source:
- Microsoft MSTIC
- Read Time:
- 5 min
Executive Summary
In a significant escalation of state-sponsored cyber espionage, Encrygma analysts, in coordination with global threat intelligence partners, have uncovered a massive expansion of the 'Salt Typhoon' (also known as GhostEmperor or FamousSparrow) campaign. The operation, which initially focused on North American telecommunications infrastructure, has now been verified to affect at least four major European tier-1 internet service providers (ISPs). The primary objective appears to be the long-term compromise of lawful interception systems, specifically those governed by the Communications Assistance for Law Enforcement Act (CALEA) in the United States and similar legal frameworks in the European Union. This breach represents a strategic failure in the security of the global surveillance apparatus, allowing a foreign adversary to intercept sensitive communications in real-time.
Threat Analysis
Salt Typhoon is a highly sophisticated Advanced Persistent Threat (APT) group with strong ties to the People's Republic of China (PRC), likely operating under the direction of the Ministry of State Security (MSS). Unlike 'Volt Typhoon,' which focuses on pre-positioning for disruptive attacks against critical infrastructure, Salt Typhoon is a pure espionage entity. Their tradecraft is characterized by extreme stealth, using custom-built malware designed specifically for network appliances such as edge routers, VPN concentrators, and firewalls. By targeting the ISP backbone rather than individual endpoints, the group achieves a 'force multiplier' effect, gaining access to the traffic of millions of users while remaining invisible to traditional endpoint detection and response (EDR) solutions.
Technical Details
The attackers utilized a combination of zero-day vulnerabilities and N-day exploits targeting end-of-life (EoL) Cisco and Juniper routing hardware. Upon gaining initial access, Salt Typhoon deployed a custom rootkit dubbed 'SPARROW-DIVE,' which resides in the router's firmware. This implant allows for the redirection of traffic at the kernel level, effectively bypassing standard logging mechanisms. The group specifically targeted the management networks responsible for lawful intercept requests. By compromising these systems, the actors were able to view existing court-ordered wiretaps and initiate their own unauthorized interceptions without the knowledge of the ISP's security operations center. They maintained persistence through the use of valid, stolen administrative credentials and the modification of SSH configurations to allow 'backdoor' access via non-standard ports.
Attribution Assessment
Encrygma assesses with high confidence that the activity is attributable to Salt Typhoon. This assessment is based on the overlap in Command and Control (C2) infrastructure used in previous 2024 campaigns, as well as the unique code signatures found in the 'SPARROW-DIVE' rootkit, which share 85% similarity with tools previously attributed to Chinese MSS-linked contractors. Furthermore, the selection of targets aligns perfectly with Beijing's strategic interest in monitoring political dissidents and foreign government officials located within the EU and North America.
Implications
The implications of this breach are catastrophic for national security. By gaining access to the 'lawful intercept' backends, Salt Typhoon has effectively turned the West's own surveillance tools against them. This allows the PRC to identify individuals under investigation by local law enforcement, monitor intelligence officers, and gather bulk data on sensitive diplomatic communications. Furthermore, the presence of such deep persistence in backbone infrastructure suggests that any attempt to purge the actors will require a massive, coordinated hardware replacement effort across multiple continents, costing billions of dollars and causing significant service interruptions.
Recommendations
- Immediate Hardware Audit: Organizations must identify and decommission any end-of-life edge routing equipment that is no longer receiving security patches.
- Out-of-Band Management: Implement strict network segmentation for CALEA and management interfaces, ensuring they are only accessible via dedicated, out-of-band management networks with multi-factor authentication (MFA).
- Firmware Integrity Monitoring: Utilize hardware-rooted trust and platform firmware resiliency (PFR) to detect unauthorized changes to router operating systems.
- Enhanced Traffic Analytics: Deploy netflow analysis tools to detect anomalous data exfiltration patterns from management subnets.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

State-Sponsored Actors Pivot to Ransomware-as-a-Cover for Global Espionage Campaigns

Global Intelligence Alert: Escalating Nation-State Exploitation of Edge Infrastructure in Q3 2026

