The Containment Era is here. →Explore

Executive Summary

In 2023, the telecommunications giant AT&T was targeted by the advanced persistent threat group Salt Typhoon, which launched a sophisticated campaign exploiting unconventional vulnerabilities. Unlike conventional attacks, Salt Typhoon focused on endpoints lacking robust detection and response (EDR), hunted for network blind spots with minimal logging, and engaged in 'living off the land' attacks—leveraging legitimate administrative tools to evade detection and persist inside networks. This multi-pronged methodology enabled deep network infiltration before discovery, ultimately jeopardizing sensitive data and service availability across AT&T’s infrastructure. Following the breach, the company reported the threat group was successfully evicted from its systems.

This incident has set a precedent, with numerous threat actors now adopting Salt Typhoon’s tactics to bypass traditional security controls. The breach highlights an urgent need for organizations to enhance monitoring, bolster endpoint visibility across all platforms, and adapt defenses for evolving attacker methodologies in critical infrastructure sectors.

Why This Matters Now

The Salt Typhoon campaign exemplifies how threat actors are rapidly innovating to exploit security gaps that fall outside standard monitoring and controls. The incident demonstrates the growing urgency for organizations—especially in critical industries like telecom—to expand detection beyond traditional endpoints and reexamine their security architecture against advanced, evasive TTPs.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach exposed deficiencies in endpoint detection coverage, network visibility gaps, and a lack of comprehensive logging—areas emphasized by frameworks like NIST 800-53 and PCI DSS.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, microsegmentation, east-west traffic security, egress policy enforcement, and centralized visibility—enabled by Cloud Network Security Fabric—would have significantly constrained or detected Salt Typhoon’s unconventional methods by limiting attack paths, detecting abnormal movements, and preventing unmonitored data exfiltration.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Rapid detection of suspicious new connections on unmanaged assets.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits blast radius of compromised accounts by enforcing strict identity-based network segmentation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detects and blocks unauthorized lateral movement between workloads.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Detects anomalous external communications and raises immediate alerts.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Blocks unauthorized or anomalous data egress from sensitive segments.

Impact (Mitigations)

Prevents undetected deletion of activity records by enforcing distributed logging and audit.

Impact at a Glance

Affected Business Functions

  • Network Operations
  • Data Security
  • Customer Communications
Operational Disruption

Estimated downtime: 30 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Unauthorized access to sensitive customer data, including call logs and personal information, leading to potential regulatory fines and loss of customer trust.

Recommended Actions

  • Expand continuous multicloud network visibility to unmanaged and traditionally unmonitored platforms.
  • Enforce fine-grained zero trust segmentation based on workload identity rather than network location alone.
  • Rigorously implement east-west traffic inspection to detect and disrupt lateral movement using legitimate admin tools.
  • Apply adaptive egress controls and FQDN-based filtering to prevent unapproved data exfiltration and C2 communications.
  • Automate anomaly response and logging to ensure attacker operations in 'shadow IT' or unconventional areas are visible and auditable.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image