Chinese State-Sponsored Hackers Targeting Telecommunications Infrastructure to Steal Sensitive Data
Recent reports indicate that the Chinese state-sponsored cyber threat group, Salt Typhoon, has escalated its espionage activities targeting global telecommunications infrastructure. This group, associated with the Ministry of State Security (MSS), has…
Recent reports indicate that the Chinese state-sponsored cyber threat group, Salt Typhoon, has escalated its espionage activities targeting global telecommunications infrastructure. This group, associated with the Ministry of State Security (MSS), has been active since at least 2019. It has been exploiting network edge devices to maintain persistence and exfiltrate sensitive communications metadata, VoIP configurations, and subscriber profiles from major telecom providers worldwide.
Salt Typhoon operates under MSS oversight, utilizing a network of front companies and state-linked contractors, such as i-SOON (Anxun Information Technology Co., Ltd.), to obscure its activities. Indictments and advisories highlight Salt Typhoon's operational ties to i-SOON, which provides infrastructure and technical support for their cyber operations.
The group's targets include the United States, United Kingdom, Taiwan, and European Union states, with confirmed breaches in over a dozen U.S. telecom firms and multiple National Guard networks. Salt Typhoon is part of China’s broader cyber intelligence architecture, categorized under the "Typhoon" taxonomy introduced by Microsoft.
Salt Typhoon's campaigns use bespoke malware, living-off-the-land binaries (LOLBINs), and stealthy router implants. The group represents a state-directed cyber espionage program within the operational apparatus of the People’s Republic of China (PRC).
This group, associated with the Ministry of State Security (MSS), has been active since at least 2019.
The group's tradecraft includes using publicly trackable domains registered with fabricated U.S. personas and ProtonMail accounts. Between 2020 and 2025, Salt Typhoon registered at least 45 domains with names like Monica Burch and Shawn Francis, often listing U.S. addresses. These domains share DNS hosts and leverage commercial SSL certificates to appear legitimate.
Despite achieving credibility through consistent templates, these patterns provide defenders with opportunities for detection through passive DNS clustering, certificate monitoring, and registrar telemetry.
Salt Typhoon exemplifies China's evolving contractor-enabled cyber espionage model, combining state tasking with commercial tradecraft. The group's domain management and edge device implants support dual-use objectives: intelligence collection and potential wartime communications disruption.
Salt Typhoon outsources infrastructure provisioning to front companies, achieving scalability and plausible deniability, complicating countermeasures. Telecom operators and government defenders should focus on DNS and certificate telemetry, monitor ProtonMail-based registrations, and deploy anomaly detection on network equipment.
Enhanced cooperation between industry, academia, and government can further refine detection methods and mitigate the group's access to critical infrastructure. Continued vigilance and collaborative threat hunting are crucial against this MSS-directed espionage program.
Based on reporting by GBHackers.
