Chinese hackers Salt Typhoon are using a custom program called JumbledPath to secretly monitor network traffic and steal sensitive data in attacks against US telecommunications providers.

Salt Typhoon is a sophisticated hacking group, active since at least 2019, primarily focusing on breaching government entities and telecommunications companies.
Recently, US authorities confirmed that Salt Typhoon was behind several successful telecom breaches, including Verizon, AT&T, Lumen Technologies, and T-Mobile. In fact, Chinese hackers managed to steal private communications from some US government officials.
See also: Chinese hackers Mustang Panda abuse MAVInject.exe
Last week, Recorded Future's Insikt Group reported that Chinese hackers Salt Typhoon targeted over 1,000 Cisco network devices to breach telecom providers between December 2024 and January 2025. More than half were located in the US, South America, and India.
Now, Cisco Talos has revealed more details about the attacks against telecommunications in the US.
Salt Typhoon hackers: Tactics
Cisco says hackers penetrated its core networking infrastructure primarily through stolen credentials. Aside from a single case involving the exploitation of Cisco's vulnerability, CVE-2018-0171, the cybersecurity company has not seen any other exploits of the bug.
“ No new Cisco vulnerabilities were discovered during this campaign ,” Cisco Talos says in its report. “ While there have been some reports that Salt Typhoon is abusing three other known Cisco vulnerabilities, we have not identified any evidence to corroborate these claims .”
The Chinese hackers Salt Typhoon primarily gained access to targeted networks using stolen credentials. However, we do not know how this initial theft occurred.
After initial access, they spread by stealing additional credentials from network device configurations and by stealing authentication traffic (SNMP, TACACS, and RADIUS).
See also: Chinese hackers combined RA World ransomware with espionage tools
They also exported device configurations via TFTP and FTP to facilitate lateral movement. These configurations contained sensitive authentication data, weakly encrypted passwords, and network mapping details.
According to Cisco Talos, the attackers used advanced methods to maintain access and avoid detection.
The hackers also modified network configurations, enabled Guest Shell access to execute commands, modified access control lists (ACLs), and created hidden accounts.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Salt Typhoon hackers use the custom malware JumbledPath
A main element of Salt Typhoon's attacks on telecom providers was monitoring network activity and stealing data, through tools such as Tcpdump, Tpacap, Embedded Packet Capture , and a custom tool called JumbledPath.
JumpedPath is a Go-based ELF binary, built for Linux-based x86_64 systems. It can run on a variety of networking devices from different manufacturers, including Cisco Nexus devices.
JumbledPath allowed Chinese hackers Salt Typhoon to initiate packet downloads on a targeted Cisco device via a jump-host, an intermediary system that made download requests appear to come from a trusted device within the network, while simultaneously masking the attacker's true location.
See also: Chinese cyberspies use new SSH backdoor
The same tool could also disable logging and delete existing logs to erase traces of malicious activity .
Cisco provides some tips for detecting Salt Typhoon activity in telecommunications provider networks:
- Monitoring unauthorized SSH activity on non-standard ports
- Monitoring for detection of log anomalies, including files ‘.bash_history’ that are missing or unusually large
- Checking for unexpected configuration changes
The telecommunications sector is an essential component of modern society, providing critical services such as communication, commerce and emergency response. As a result, it is increasingly targeted by malicious actors. Chinese hackers use various methods to penetrate sensitive systems and gain access to valuable data.
In response to this growing threat landscape, governments worldwide are being called upon to implement regulations and guidelines to strengthen cybersecurity practices in the telecommunications sector (against Salt Typhoon or other threats).
Source: www.bleepingcomputer.com
