The Chinese state-sponsored group Salt Typhoon has been targeting U.S. telecommunications providers using a custom tool called JumbledPath to stealthily monitor network traffic and capture sensitive data. In several cases, the attackers gained access to core networking infrastructure, primarily by using legitimate login credentials, though in one instance, they likely exploited a known Cisco vulnerability. A key tactic in this campaign is the use of living-off-the-land (LOTL) techniques, enabling the threat actors to blend into existing network environments and evade detection while gathering critical information.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox