tactical Threat Intelligencemedium

WIRED: Salt Typhoon keeps hacking telecoms despite sanctions

Thu, Feb 13, 2025, 08:00 AM UTC·Feb 13, 2025· Adversary: China (PRC) (ADV-CN)

Summary

Bottom line: public reporting confirmed the group continued operations through the sanctions and indictment cycle. Assume designation has deterrence value for financiers, not for the operators themselves.

Key claims· extracted from reporting

  • Bottom line: public reporting confirmed the group continued operations through the sanctions and indictment cycle.Low · 20%
    action verbnamed entity
    Source: WIRED
  • Assume designation has deterrence value for financiers, not for the operators themselves.Low · 10%
    named entity
    Source: WIRED

Heuristic extraction, verify against the original report before citing.

Tags· click to alert

Story timeline

5 updates · 222 days
  1. Feb 13, 2025·mediumcurrentWIRED
    WIRED: Salt Typhoon keeps hacking telecoms despite sanctions

Key takeaways

The three things worth remembering from this item.

  1. 1Bottom line: WIRED: Salt Typhoon keeps hacking telecoms despite sanctions[1]
  2. 2Salt Typhoon activity is the driver here, and the objective is what should shape your response, not the tool names.[1][2]
  3. 3Defensively, the highest-leverage move is coverage for T1190 · Exploit Public-Facing Application, because it is a behavior class rather than an indicator.[1][2]

Concepts in this story

Each concept opens in layers: plain English, technical, then expert.

Salt Typhoon

China · Very high tempo

Salt Typhoon is a China linked hacking group. In plain terms, they break into us telecom carriers, isps, government communications and stay there. Their goal is to strategic sigint collection against us carriers and senior officials.

Why it matters
Beijing-nexus operations are the pacing threat in US cyber policy: the concern is pre-positioning inside critical infrastructure for use during a crisis, not day-to-day theft.[1][2]
Common misconception
That every Chinese intrusion is intellectual property theft. Pre-positioning groups deliberately steal nothing, which is exactly why they go unnoticed.
Cyber Kill ChainNIST CSF 2.0, Identify, Detect, Respond
Sources for this concept
  1. [1]Salt Typhoon breach exposes US lawful-intercept systems· Public incident reporting· 2024-12-15 00:00Z
  2. [2]WIRED: Salt Typhoon keeps hacking telecoms despite sanctions· WIRED· 2025-02-13 08:00Z

T1190 · Exploit Public-Facing Application

Initial Access · used by 13 tracked groups

Exploit Public-Facing Application is how an attacker initial access works in practice. Edge devices and VPN appliances (Ivanti, Fortinet, Citrix, Cisco) exploited within hours of CVE disclosure.

Why it matters
This is a initial access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1190 Tactic: Initial Access
Sources for this concept
  1. [1]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190
  2. [2]WIRED: Salt Typhoon keeps hacking telecoms despite sanctions· WIRED· 2025-02-13 08:00Z

T1505.003 · Server Software Component: Web Shell

Persistence · used by 5 tracked groups

Server Software Component: Web Shell is how an attacker persistence works in practice. Web shells planted on perimeter devices and Exchange servers for durable re-entry.

Why it matters
This is a persistence behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1505.003 Tactic: Persistence
Sources for this concept
  1. [1]T1505.003 · Server Software Component: Web Shell· MITRE ATT&CK T1505.003
  2. [2]WIRED: Salt Typhoon keeps hacking telecoms despite sanctions· WIRED· 2025-02-13 08:00Z

T1114.002 · Email Collection: Remote Email Collection

Collection · used by 6 tracked groups

Email Collection: Remote Email Collection is how an attacker collection works in practice. Targeted mailbox harvesting from Exchange and M365 tenants.

Why it matters
This is a collection behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1114.002 Tactic: Collection
Sources for this concept
  1. [1]T1114.002 · Email Collection: Remote Email Collection· MITRE ATT&CK T1114.002
  2. [2]WIRED: Salt Typhoon keeps hacking telecoms despite sanctions· WIRED· 2025-02-13 08:00Z

T1071.001 · Application Layer Protocol: Web Protocols

Command and Control · used by 5 tracked groups

Application Layer Protocol: Web Protocols is how an attacker command and control works in practice. Custom HTTPS tunnels and domain fronting for beacon traffic.

Why it matters
This is a command and control behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1071.001 Tactic: Command and Control
Sources for this concept
  1. [1]T1071.001 · Application Layer Protocol: Web Protocols· MITRE ATT&CK T1071.001
  2. [2]WIRED: Salt Typhoon keeps hacking telecoms despite sanctions· WIRED· 2025-02-13 08:00Z
Sources for these takeaways
  1. [1]WIRED: Salt Typhoon keeps hacking telecoms despite sanctions· WIRED· 2025-02-13 08:00Z
  2. [2]Salt Typhoon breach exposes US lawful-intercept systems· Public incident reporting· 2024-12-15 00:00Z
  3. [3]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190

Knowledge check

Five questions. Answers explain the reasoning, not just the result.

Question 1 of 5

Which nexus is Salt Typhoon attributed to in public reporting?

Question 2 of 5

Which sector is a primary target for Salt Typhoon?

Question 3 of 5

Which ATT&CK tactic does T1190 (Exploit Public-Facing Application) belong to?

Question 4 of 5

Which ATT&CK tactic does T1505.003 (Server Software Component: Web Shell) belong to?

Question 5 of 5

Which ATT&CK tactic does T1114.002 (Email Collection: Remote Email Collection) belong to?

Answer all 5 to check.
Estimated mastery
First time on this material.
New · 0/100