Salt Typhoon U.S. Telecommunications Wiretap Infrastructure Infiltration
Key Facts
- Legal Status: INVESTIGATION in Federal Bureau of Investigation & CISA Joint Investigation.
- Primary Target Sector: Telecommunications & Critical Infrastructure.
- Documented Financial Loss: $500.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2024-21887, CVE-2024-3400) combined with targeted spearphishing and stolen remote access credentials.
Operational & Financial Fallout
National security impact, emergency carrier hardware rip-and-replace, and lawful intercept architectural overhaul. Impacted Telecommunications & Critical Infrastructure infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2024-21887, CVE-2024-3400) combined with targeted spearphishing and stolen remote access credentials.
Adversary Kill Chain Flow
1 Documented PhasesThreat actors exploited edge firewall and VPN appliance vulnerabilities to compromise peripheral carrier edge routers.
National security impact, emergency carrier hardware rip-and-replace, and lawful intercept architectural overhaul. Impacted Telecommunications & Critical Infrastructure infrastructure and associated victim operations.
Procedural & Incident Timeline
Salt Typhoon establishes persistence inside major U.S. telecommunications carrier core networks.
Investigators discover unauthorized access to lawful intercept CALEA interfaces.
FBI and CISA issue joint public warning detailing Chinese state-sponsored targeting of commercial telcos.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Threat actors exploited edge firewall and VPN appliance vulnerabilities to compromise peripheral carrier edge routers." | CISA Joint Cybersecurity Advisory on PRC Compromise of Commercial Telecommunications | reviewed |
| T1040 | "Actors modified Cisco and Juniper router configurations to packet-sniff internal telco switching networks and intercept CALEA legal intercept data streams." | FBI/CISA Technical Analysis Bulletin ¶ 12 | reviewed |