Chinese hackers Salt Typhoon breached US Internet Service Providers (ISPs) as part of a cyberespionage.

The Chinese team has been named “Salt Typhoon” by Microsoft , but is also known as FamousSparrow and GhostEmperor.
“Researchers are investigating whether the attackers gained access to Cisco Systems routers, key network components that route much of the Internet’s traffic,” said The Wall Street Journal, which first reported the news.
See also: Chinese hackers distribute EAGLEDOOR malware via GeoServer flaw
The ultimate goal of Chinese hackers is to stay inside the network of American Internet service providers, to collect sensitive data or launch a damaging attack.
The Salt Typhoon hackers became known in October 2021, when Russian cybersecurity Kasperksy unveiled a long-running operation targeting Southeast Asiato deploy a rootkit called Demodex.
The campaign's targets included high-profile entities in Malaysia, Thailand, Vietnam, Indonesia, Egypt, Ethiopia and Afghanistan.
In July 2024, Sygnia revealed that a customer was compromised by Chinese hackers Salt Typhoon (in 2023) with the aim of penetrating one of the business partner networks.
See also: US says Chinese Botnet compromises 260,000 SOHO devices

“During the investigation, multiple servers, workstations, and users were found to be compromised by a threat that deployed various tools to communicate with a set of [command and control] servers,” the company said. “One of these tools was identified as a variant of Demodex.”
See also: DOJ charges Chinese engineer with spear phishing against NASA
Chinese hackers (e.g. Salt Typhoon) pose a significant threat to critical infrastructure . That’s why Republicans on the House Homeland Security Committee have introduced a new billto address the threats posed by Chinese hackers. The bill was introduced by Representative Laurel Lee on September 24 and calls for the creation of a task force led by the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI. The task force would focus on addressing threats and cyberattacks from Chinese hackers.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
