Chinese State-Sponsored Hackers Exploiting Network Edge Devices to Harvest Sensitive Data
Since 2019, the cyber threat group known as Salt Typhoon, believed to be state-sponsored by China, has been targeting global telecommunications infrastructure. This group exploits network edge devices to establish persistent attacks and collect…
Since 2019, the cyber threat group known as Salt Typhoon, believed to be state-sponsored by China, has been targeting global telecommunications infrastructure. This group exploits network edge devices to establish persistent attacks and collect significant amounts of sensitive data.
Aligned with the Chinese Ministry of State Security (MSS), Salt Typhoon focuses on long-term signals intelligence (SIGINT) collection. The group uses front companies and contractor networks to obscure its activities, maintaining oversight from Beijing.
Salt Typhoon's operations have affected multiple regions, including the United States, United Kingdom, Taiwan, and the European Union. The group has compromised at least a dozen U.S. telecom providers and numerous state National Guard networks.
The group's attacks utilize custom malware, living-off-the-land binaries (LOLBINs), and stealthy firmware implants on routers, VPN gateways, and firewalls. These techniques enable the interception of VoIP configurations, lawful intercept logs, subscriber metadata, and call detail records.
Recent intelligence has linked Salt Typhoon to pseudo-private contractor firms such as i-SOON (Anxun Information Technology Co., Ltd.), Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong, and Sichuan Zhixin Ruijie. These entities provide domain registration pipelines, leased infrastructure, technical support, and custom tools.
Salt Typhoon is known for its modular, industrialized infrastructure. The group routinely registers English-language domains using fabricated U.S. personas and acquires commercial domain-validated SSL certificates from providers such as GoDaddy and Sectigo to enhance legitimacy.
This group exploits network edge devices to establish persistent attacks and collect significant amounts of sensitive data.
Its operations are a state-directed cyber espionage program embedded within the People’s Republic of China’s operational apparatus.
U.S. Telecom Metadata Breach (2024): Subscriber metadata and lawful intercept logs were exfiltrated from major telecom providers through exploited router and firewall vulnerabilities. National Guard Network Intrusions (March–December 2024): State-level Guard networks suffered intrusions via VPN gateway exploits, capturing critical network information. British Critical Infrastructure Breach (2023–2024): UK government and military communications systems were compromised with deep-persistence implants. EU Router Hijacking (2022–2023): Several ISPs across the Netherlands, Germany, and France experienced firmware implants and backdoored updates.
Attribution efforts have identified key individuals involved in Salt Typhoon’s operations, including Yin Kecheng and Zhou Shuai. Their roles highlight the group's layered adversary model, which separates strategic brokerage, domain logistics, and technical deployment.
Salt Typhoon's hybrid operating model reflects a shift in PRC cyber doctrine toward privatized, scalable espionage. This approach combines legitimate commercial R&D with covert offensive capabilities.
Defenders can leverage the group's predictable domain naming patterns, bulk SSL certificate procurement, and shared DNS clusters for detection. Monitoring passive DNS, registrar telemetry, and SSL certificate issuances can help identify emerging campaigns early.
To mitigate long-term persistence, telecom operators and critical infrastructure providers should enhance firmware security, enforce rigorous configuration management, and deploy robust anomaly detection systems.
International collaboration is crucial in tracking, attributing, and disrupting state-aligned cyber espionage programs targeting global communications infrastructure.
Based on reporting by GBHackers.
