No Scroll News

U.S. Telecom Attacks by Chinese Group 'Salt Typhoon' Persist into 2025

Federal cyber authorities warn that Chinese-sponsored group Salt Typhoon continues its cyberattacks on U.S. telecom networks into 2025, having infiltrated at least nine companies and leaving network vulnerabilities intact.
Published on April 9, 2025

Federal cyber authorities continue to confront persistent intrusions by the Chinese-sponsored group Salt Typhoon, which remains active in compromising U.S. telecom networks. The group has infiltrated at least nine telecom companies, with attackers retaining access through methods such as the use of compromised credentials and even an older Cisco vulnerability (CVE-2018-0171), as reported by Cisco Talos in February 2025. A custom-built malware named 'JumbledPath' has been identified, facilitating remote connections between devices and external servers.

Recent government and industry responses underline the urgency of bolstering network security. On January 17, 2025, Reuters highlighted comments by the outgoing FCC head who termed the cyberattacks as a clarion call for enhanced security measures. Additional details, such as the White House confirmation of a ninth telecom breach in late December 2024 and Treasury sanctions imposed on cyber operatives linked to Salt Typhoon, further illustrate the extensive threat facing critical telecommunications infrastructure.


Sources
Cybersecurity DiveCybersecurity DiveReutersAP NewsReuters