HomeSecurityChina's Salt Typhoon hacked the US National Guard

China's Salt Typhoon hacked the US National Guard

The hacking group Salt Typhoon breached the network of a US state National Guard unit, collected configuration information and monitored its communication with other units, according to a report by the US Department of Defense.

See also: Possible member of the Silk Typhoon group arrested

Salt Typhoon National Guard

The state-backed threat actorwas previously accused of cyberattacks against US telecommunications giants AT&T and Verizon, as well as Lumen Technologies and other providers inside and outside the US, with the aim of breaching eavesdropping systems.

Last month, the Canadian Centre for Cybersecurity and the FBI warned that this APT group had also targeted telecommunications providers in Canada, intercepting call records and private communications.

According to a June report obtained by NBC News, the U.S. Department of Defense warned that Salt Typhoon breached a U.S. state National Guard network, gaining valuable information that could facilitate further attacks on networks of other units and state-level cybersecurity partners . The breached network, the report said, lasted from March to December 2024, extracting configuration data and collecting information to and from the networks of “ corresponding agencies in every other U.S. state and at least four U.S. territories .”

See also: Canada: Salt Typhoon hackers breached telecommunications company

China's Salt Typhoon hacked the US National Guard

According to the report, between January and March 2024, Chinese hackers stole configuration files from other U.S. government agencies and critical infrastructure, including at least two state-level agencies. The Department of Defense says that in 2023 and 2024, the Salt Typhoon group stole a total of 1,462 network configuration files from approximately 70 U.S. government agencies and critical infrastructure agencies , belonging to 12 sectors, including energy, communications, transportation and water/wastewater.

To gain initial access, the hackers exploited known vulnerabilities in Cisco and Palo Alto Networks peripherals, including CVE-2018-0171, CVE-2023-20198, CVE-2023-20273 , and CVE-2024-3400, the report states.

See also: Chinese hackers Salt Typhoon breached Viasat

The breach of National Guard networks, according to the Department of Defense, could undermine local efforts to protect critical infrastructure from cyberattacks, as National Guard units in 14 states are integrated into centers responsible for collecting threat intelligence, while the unit in one state provides cyber defense services.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS