HomeSecurityChinese hackers breach telecommunications via Cisco routers

Chinese hackers breach telecommunications through Cisco routers

Chinese hackers Salt Typhoon continue to target telecommunications companiesaround the world, and in the US, breaches are primarily occurring via unpatched Cisco IOS XE devices.

Chinese hackers Salt Typhoon targets telecom providers Cisco

Researchers at Recorded Future report that the Chinese group has exploited the privilege escalation vulnerability CVE-2023-20198 and the Web UI command injection vulnerability, CVE-2023-20273.

See also: Critical Cisco ISE bug allows executing commands as root

These ongoing attacks have already led to network breaches of several telecommunications providers, including a US internet service provider (ISP), an American telecommunications provider, a telecommunications provider , an Italian ISP, and a major Thai telecommunications provider.

Researchers identified compromised and reconfigured Cisco devices on the targets' networks, which were communicating with servers controlled by the Chinese hackers Salt Typhoon.

Between December 2024 and January 2025, the Salt Typhoon group targeted over 1,000 Cisco network devices. More than half of them were located in the US, South America, and India.

Two years ago, the two Cisco vulnerabilities were used in attacks as zero-days, compromising more than 50,000 Cisco IOS XE devices and allowing backdoor malware deployment via malicious privileged accounts. The two vulnerabilities were among the top four most frequently exploited in 2023.

See also: Multiple vulnerabilities in Cisco SNMP allow DoS attacks

The researchers advise network administrators who operate Cisco IOS XE devices exposed to the Internet to apply available security updates as soon as possible. They also recommend avoiding exposing administration interfaces and non-core services directly to the Internet.

Chinese hackers breach telecommunications through Cisco routers
Chinese hackers breach telecom providers using Cisco devices

These breaches are part of a broader campaign confirmed by the FBI and CISA in October. In these attacks, Chinese hackers breached several major telecommunications providers in the US and other countries.

The telecommunications sector is an essential component of modern society, providing critical services such as communication, commerce and emergency response. As a result, it is increasingly targeted by malicious actors. Chinese hackers use various methods to penetrate sensitive systems and gain access to valuable data.

See also: Cisco warns of DoS flaw

In response to this growing threat landscape, governments around the world are being urged to implement regulations and guidelines to strengthen cybersecurity practices in the telecommunications industry (against Salt Typhoon or other threats).

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS