Executive Summary
In 2023, the telecommunications giant AT&T was targeted by the advanced persistent threat group Salt Typhoon, which launched a sophisticated campaign exploiting unconventional vulnerabilities. Unlike conventional attacks, Salt Typhoon focused on endpoints lacking robust detection and response (EDR), hunted for network blind spots with minimal logging, and engaged in 'living off the land' attacks—leveraging legitimate administrative tools to evade detection and persist inside networks. This multi-pronged methodology enabled deep network infiltration before discovery, ultimately jeopardizing sensitive data and service availability across AT&T’s infrastructure. Following the breach, the company reported the threat group was successfully evicted from its systems.
This incident has set a precedent, with numerous threat actors now adopting Salt Typhoon’s tactics to bypass traditional security controls. The breach highlights an urgent need for organizations to enhance monitoring, bolster endpoint visibility across all platforms, and adapt defenses for evolving attacker methodologies in critical infrastructure sectors.
Why This Matters Now
The Salt Typhoon campaign exemplifies how threat actors are rapidly innovating to exploit security gaps that fall outside standard monitoring and controls. The incident demonstrates the growing urgency for organizations—especially in critical industries like telecom—to expand detection beyond traditional endpoints and reexamine their security architecture against advanced, evasive TTPs.
Attack Path Analysis
Salt Typhoon initiated their attack by exploiting platforms lacking endpoint detection, targeting unconventional entry points with minimal monitoring. Once inside, they leveraged weak access controls and possibly misconfigurations to escalate privileges, gaining broader access. The attackers then moved laterally by exploiting east-west traffic paths and internal trust relationships, using legitimate admin tools and 'living off the land' techniques to evade detection. Command and control was maintained through covert channels and exploitation of gaps in logging, making malicious activity harder to track. Data was exfiltrated via outbound channels, potentially using approved applications or encrypted channels to elude monitoring. Finally, the operation sought to maintain persistence and obscure its tracks, increasing operational impact while minimizing opportunities for forensic investigation.
Kill Chain Progression
Initial Compromise
Description
Attackers targeted endpoints and platforms with insufficient monitoring and lacking EDR coverage, exploiting weak points outside the scope of traditional security controls.
Related CVEs
CVE-2018-0171
CVSS 9.8A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.
Affected Products:
Cisco IOS and IOS XE – Various
Exploit Status:
exploited in the wildCVE-2023-20198
CVSS 10A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to create an account on an affected device with privilege level 15 access.
Affected Products:
Cisco IOS XE – Various
Exploit Status:
exploited in the wildCVE-2023-20273
CVSS 7.8A vulnerability in the command-line interface (CLI) of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.
Affected Products:
Cisco IOS XE – Various
Exploit Status:
exploited in the wildCVE-2024-21887
CVSS 9.8A command injection vulnerability in the web component of Ivanti Connect Secure and Ivanti Policy Secure allows an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system.
Affected Products:
Ivanti Connect Secure and Policy Secure – Various
Exploit Status:
exploited in the wildCVE-2024-3400
CVSS 9.8A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS allows an unauthenticated, remote attacker to execute arbitrary code with root privileges on the firewall.
Affected Products:
Palo Alto Networks PAN-OS – Various
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
System Binary Proxy Execution
Impair Defenses
Indicator Removal on Host
Obfuscated Files or Information
Non-Application Layer Protocol
Ingress Tool Transfer
Inter-Process Communication
Windows Management Instrumentation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Implement Automated Audit Trails
Control ID: 10.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02
NIS2 Directive – Cybersecurity Risk Management and Reporting
Control ID: Article 21
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Continuous Authentication and Least Privilege
Control ID: Identity - Advanced
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Primary target of Salt Typhoon APT campaign, facing unconventional attack techniques bypassing traditional EDR controls and exploiting unprotected platforms.
Computer/Network Security
Must adapt security strategies as APT groups exploit endpoint detection gaps, unlogged network areas, and legitimate administrative tools for persistence.
Government Administration
Critical infrastructure vulnerable to living-off-the-land attacks targeting platforms without EDR coverage, requiring enhanced zero trust segmentation capabilities.
Information Technology/IT
IT operations face threats from attackers using legitimate administrative tools and targeting areas lacking comprehensive logging and monitoring capabilities.
Sources
- Telecom exec: Salt Typhoon inspiring other hackers to use unconventional techniqueshttps://cyberscoop.com/telecom-exec-salt-typhoon-inspiring-other-hackers-to-use-unconventional-techniques/Verified
- Chinese hackers were able to breach US National Guard and stay undetected for monthshttps://www.techradar.com/pro/security/chinese-hackers-were-able-to-breach-us-national-guard-and-stay-undetected-for-monthsVerified
- Understanding Salt Typhoon: A Deep Dive into the Tactics of an APT Group Targeting U.S. Infrastructurehttps://www.madsquirreltech.com/2025/06/understanding-salt-typhoon-a-deep-dive-into-the-tactics-of-an-apt-group-targeting-u-s-infrastructure/Verified
- THREAT ADVISORYhttps://hivepro.com/wp-content/uploads/2025/02/TA2025053.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, microsegmentation, east-west traffic security, egress policy enforcement, and centralized visibility—enabled by Cloud Network Security Fabric—would have significantly constrained or detected Salt Typhoon’s unconventional methods by limiting attack paths, detecting abnormal movements, and preventing unmonitored data exfiltration.
Control: Multicloud Visibility & Control
Mitigation: Rapid detection of suspicious new connections on unmanaged assets.
Control: Zero Trust Segmentation
Mitigation: Limits blast radius of compromised accounts by enforcing strict identity-based network segmentation.
Control: East-West Traffic Security
Mitigation: Detects and blocks unauthorized lateral movement between workloads.
Control: Threat Detection & Anomaly Response
Mitigation: Detects anomalous external communications and raises immediate alerts.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unauthorized or anomalous data egress from sensitive segments.
Prevents undetected deletion of activity records by enforcing distributed logging and audit.
Impact at a Glance
Affected Business Functions
- Network Operations
- Data Security
- Customer Communications
Estimated downtime: 30 days
Estimated loss: $5,000,000
Unauthorized access to sensitive customer data, including call logs and personal information, leading to potential regulatory fines and loss of customer trust.
Recommended Actions
Key Takeaways & Next Steps
- • Expand continuous multicloud network visibility to unmanaged and traditionally unmonitored platforms.
- • Enforce fine-grained zero trust segmentation based on workload identity rather than network location alone.
- • Rigorously implement east-west traffic inspection to detect and disrupt lateral movement using legitimate admin tools.
- • Apply adaptive egress controls and FQDN-based filtering to prevent unapproved data exfiltration and C2 communications.
- • Automate anomaly response and logging to ensure attacker operations in 'shadow IT' or unconventional areas are visible and auditable.



