20 February 2025

China’s Salt Typhoon hackers targeting Cisco devices used by telcos, universities

Jonathan Greig

China’s Salt Typhoon campaign to breach telecommunications companies has continued through the new year despite efforts by governments to stop the hackers, researchers said Thursday.

Recorded Future’s Insikt Group identified a campaign in December and January that involved attempts to compromise more than 1,000 Cisco network devices globally, many of which are associated with telecommunications providers. The Record is an editorially independent unit of Recorded Future.

Among the targeted organizations was a South African telecom, as well as a U.S.-based affiliate of a UK telecommunications company.

“The group likely compiled a list of target devices based on their association with telecommunications providers' networks,” the researchers said.

Insikt Group observed seven total compromised Cisco network devices communicating with Salt Typhoon infrastructure — including those connected to telecommunications companies in the U.S. and South Africa, as well as others in Italy and Thailand.

No comments: