strategic Cyber Diplomacy & Normscritical

Joint Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency statement on telecom targeting

Wed, Nov 13, 2024, 05:00 PM UTC·Nov 13, 2024· Critical Infra: Communications (CI-COMMS)

Summary

Bottom line: the two agencies publicly confirmed a broad People's Republic of China espionage campaign inside multiple telecommunications carriers, including call records and lawful intercept systems. It set the baseline for every later Salt Typhoon action.

Key claims· extracted from reporting

  • Bottom line: the two agencies publicly confirmed a broad People's Republic of China espionage campaign inside multiple telecommunications carriers, including call records and lawful intercept systems.Low · 20%
    action verbnamed entity×4
  • It set the baseline for every later Salt Typhoon action.Low · 10%
    named entity

Heuristic extraction, verify against the original report before citing.

Tags· click to alert

Story timeline

3 updates · 93 days
  1. Nov 13, 2024·criticalcurrentFBI / CISA joint statement
    Joint Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency statement on telecom targeting

Key takeaways

The three things worth remembering from this item.

  1. 1Bottom line: Joint Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency statement on telecom targeting[1]
  2. 2Salt Typhoon activity is the driver here, and the objective is what should shape your response, not the tool names.[1][2]
  3. 3Defensively, the highest-leverage move is coverage for T1190 · Exploit Public-Facing Application, because it is a behavior class rather than an indicator.[1][2]

Concepts in this story

Each concept opens in layers: plain English, technical, then expert.

Salt Typhoon

China · Very high tempo

Salt Typhoon is a China linked hacking group. In plain terms, they break into us telecom carriers, isps, government communications and stay there. Their goal is to strategic sigint collection against us carriers and senior officials.

Why it matters
Beijing-nexus operations are the pacing threat in US cyber policy: the concern is pre-positioning inside critical infrastructure for use during a crisis, not day-to-day theft.[1][2]
Common misconception
That every Chinese intrusion is intellectual property theft. Pre-positioning groups deliberately steal nothing, which is exactly why they go unnoticed.
Cyber Kill ChainNIST CSF 2.0, Identify, Detect, Respond
Sources for this concept
  1. [1]Salt Typhoon breach exposes US lawful-intercept systems· Public incident reporting· 2024-12-15 00:00Z
  2. [2]Joint Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency statement on telecom targeting· FBI / CISA joint statement· 2024-11-13 17:00Z

T1190 · Exploit Public-Facing Application

Initial Access · used by 13 tracked groups

Exploit Public-Facing Application is how an attacker initial access works in practice. Edge devices and VPN appliances (Ivanti, Fortinet, Citrix, Cisco) exploited within hours of CVE disclosure.

Why it matters
This is a initial access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1190 Tactic: Initial Access
Sources for this concept
  1. [1]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190
  2. [2]Joint Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency statement on telecom targeting· FBI / CISA joint statement· 2024-11-13 17:00Z

T1505.003 · Server Software Component: Web Shell

Persistence · used by 5 tracked groups

Server Software Component: Web Shell is how an attacker persistence works in practice. Web shells planted on perimeter devices and Exchange servers for durable re-entry.

Why it matters
This is a persistence behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1505.003 Tactic: Persistence
Sources for this concept
  1. [1]T1505.003 · Server Software Component: Web Shell· MITRE ATT&CK T1505.003
  2. [2]Joint Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency statement on telecom targeting· FBI / CISA joint statement· 2024-11-13 17:00Z

T1114.002 · Email Collection: Remote Email Collection

Collection · used by 6 tracked groups

Email Collection: Remote Email Collection is how an attacker collection works in practice. Targeted mailbox harvesting from Exchange and M365 tenants.

Why it matters
This is a collection behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1114.002 Tactic: Collection
Sources for this concept
  1. [1]T1114.002 · Email Collection: Remote Email Collection· MITRE ATT&CK T1114.002
  2. [2]Joint Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency statement on telecom targeting· FBI / CISA joint statement· 2024-11-13 17:00Z

T1071.001 · Application Layer Protocol: Web Protocols

Command and Control · used by 5 tracked groups

Application Layer Protocol: Web Protocols is how an attacker command and control works in practice. Custom HTTPS tunnels and domain fronting for beacon traffic.

Why it matters
This is a command and control behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1071.001 Tactic: Command and Control
Sources for this concept
  1. [1]T1071.001 · Application Layer Protocol: Web Protocols· MITRE ATT&CK T1071.001
  2. [2]Joint Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency statement on telecom targeting· FBI / CISA joint statement· 2024-11-13 17:00Z
Sources for these takeaways
  1. [1]Joint Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency statement on telecom targeting· FBI / CISA joint statement· 2024-11-13 17:00Z
  2. [2]Salt Typhoon breach exposes US lawful-intercept systems· Public incident reporting· 2024-12-15 00:00Z
  3. [3]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190

Knowledge check

Five questions. Answers explain the reasoning, not just the result.

Question 1 of 5

Which nexus is Salt Typhoon attributed to in public reporting?

Question 2 of 5

Which sector is a primary target for Salt Typhoon?

Question 3 of 5

Which ATT&CK tactic does T1190 (Exploit Public-Facing Application) belong to?

Question 4 of 5

Which ATT&CK tactic does T1505.003 (Server Software Component: Web Shell) belong to?

Question 5 of 5

Which ATT&CK tactic does T1114.002 (Email Collection: Remote Email Collection) belong to?

Answer all 5 to check.
Estimated mastery
First time on this material.
New · 0/100