strategic Cyber Diplomacy & Normshigh

Treasury sanctions Sichuan Juxinhe Network Technology over Salt Typhoon telecom intrusions

Fri, Jan 17, 2025, 03:00 PM UTC·Jan 17, 2025· Adversary: China (PRC) (ADV-CN)

Summary

Bottom line: the Office of Foreign Assets Control designated a Sichuan firm tied to the telecommunications campaign and an actor linked to the Treasury network compromise. Expect sanctions to keep running ahead of, not after, technical remediation.

Key claims· extracted from reporting

  • Bottom line: the Office of Foreign Assets Control designated a Sichuan firm tied to the telecommunications campaign and an actor linked to the Treasury network compromise.Low · 10%
    named entity×5
  • Expect sanctions to keep running ahead of, not after, technical remediation.Low · 10%
    named entity

Heuristic extraction, verify against the original report before citing.

Tags· click to alert

Story timeline

5 updates · 222 days
  1. Jan 17, 2025·highcurrentUS Department of the Treasury
    Treasury sanctions Sichuan Juxinhe Network Technology over Salt Typhoon telecom intrusions

Key takeaways

The three things worth remembering from this item.

  1. 1Bottom line: Treasury sanctions Sichuan Juxinhe Network Technology over Salt Typhoon telecom intrusions[1]
  2. 2Salt Typhoon activity is the driver here, and the objective is what should shape your response, not the tool names.[1][2]
  3. 3Defensively, the highest-leverage move is coverage for T1190 · Exploit Public-Facing Application, because it is a behavior class rather than an indicator.[1][2]

Concepts in this story

Each concept opens in layers: plain English, technical, then expert.

Salt Typhoon

China · Very high tempo

Salt Typhoon is a China linked hacking group. In plain terms, they break into us telecom carriers, isps, government communications and stay there. Their goal is to strategic sigint collection against us carriers and senior officials.

Why it matters
Beijing-nexus operations are the pacing threat in US cyber policy: the concern is pre-positioning inside critical infrastructure for use during a crisis, not day-to-day theft.[1][2]
Common misconception
That every Chinese intrusion is intellectual property theft. Pre-positioning groups deliberately steal nothing, which is exactly why they go unnoticed.
Cyber Kill ChainNIST CSF 2.0, Identify, Detect, Respond
Sources for this concept
  1. [1]Salt Typhoon breach exposes US lawful-intercept systems· Public incident reporting· 2024-12-15 00:00Z
  2. [2]Treasury sanctions Sichuan Juxinhe Network Technology over Salt Typhoon telecom intrusions· US Department of the Treasury· 2025-01-17 15:00Z

T1190 · Exploit Public-Facing Application

Initial Access · used by 13 tracked groups

Exploit Public-Facing Application is how an attacker initial access works in practice. Edge devices and VPN appliances (Ivanti, Fortinet, Citrix, Cisco) exploited within hours of CVE disclosure.

Why it matters
This is a initial access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1190 Tactic: Initial Access
Sources for this concept
  1. [1]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190
  2. [2]Treasury sanctions Sichuan Juxinhe Network Technology over Salt Typhoon telecom intrusions· US Department of the Treasury· 2025-01-17 15:00Z

T1505.003 · Server Software Component: Web Shell

Persistence · used by 5 tracked groups

Server Software Component: Web Shell is how an attacker persistence works in practice. Web shells planted on perimeter devices and Exchange servers for durable re-entry.

Why it matters
This is a persistence behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1505.003 Tactic: Persistence
Sources for this concept
  1. [1]T1505.003 · Server Software Component: Web Shell· MITRE ATT&CK T1505.003
  2. [2]Treasury sanctions Sichuan Juxinhe Network Technology over Salt Typhoon telecom intrusions· US Department of the Treasury· 2025-01-17 15:00Z

T1114.002 · Email Collection: Remote Email Collection

Collection · used by 6 tracked groups

Email Collection: Remote Email Collection is how an attacker collection works in practice. Targeted mailbox harvesting from Exchange and M365 tenants.

Why it matters
This is a collection behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1114.002 Tactic: Collection
Sources for this concept
  1. [1]T1114.002 · Email Collection: Remote Email Collection· MITRE ATT&CK T1114.002
  2. [2]Treasury sanctions Sichuan Juxinhe Network Technology over Salt Typhoon telecom intrusions· US Department of the Treasury· 2025-01-17 15:00Z

T1071.001 · Application Layer Protocol: Web Protocols

Command and Control · used by 5 tracked groups

Application Layer Protocol: Web Protocols is how an attacker command and control works in practice. Custom HTTPS tunnels and domain fronting for beacon traffic.

Why it matters
This is a command and control behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1071.001 Tactic: Command and Control
Sources for this concept
  1. [1]T1071.001 · Application Layer Protocol: Web Protocols· MITRE ATT&CK T1071.001
  2. [2]Treasury sanctions Sichuan Juxinhe Network Technology over Salt Typhoon telecom intrusions· US Department of the Treasury· 2025-01-17 15:00Z
Sources for these takeaways
  1. [1]Treasury sanctions Sichuan Juxinhe Network Technology over Salt Typhoon telecom intrusions· US Department of the Treasury· 2025-01-17 15:00Z
  2. [2]Salt Typhoon breach exposes US lawful-intercept systems· Public incident reporting· 2024-12-15 00:00Z
  3. [3]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190

Knowledge check

Five questions. Answers explain the reasoning, not just the result.

Question 1 of 5

Which nexus is Salt Typhoon attributed to in public reporting?

Question 2 of 5

Which sector is a primary target for Salt Typhoon?

Question 3 of 5

Which ATT&CK tactic does T1190 (Exploit Public-Facing Application) belong to?

Question 4 of 5

Which ATT&CK tactic does T1505.003 (Server Software Component: Web Shell) belong to?

Question 5 of 5

Which ATT&CK tactic does T1114.002 (Email Collection: Remote Email Collection) belong to?

Answer all 5 to check.
Estimated mastery
First time on this material.
New · 0/100