Executive Summary
Between March and December 2023, the Chinese state-sponsored threat group Salt Typhoon infiltrated the US National Guard’s networks, leveraging advanced persistent techniques to maintain undetected access for nearly a year. Attackers exploited security gaps, targeting unencrypted east-west and outbound network traffic, and exfiltrated sensitive operational and personnel data. The intrusion demonstrated advanced lateral movement, zero trust segmentation evasions, and targeted data exfiltration—all while remaining covert to standard detection and response tools initially. The resulting breach has exposed critical military data, presenting increased risks to operational integrity and individual privacy for National Guard personnel.
This incident reflects a growing pattern of state-backed threat actors expanding targeting against US government and defense organizations, using stealthy persistence, multi-cloud exploitation, and sophisticated attack campaigns. It underscores urgent needs for continuous monitoring, encrypted network traffic, and zero trust strategies across hybrid and cloud infrastructure.
Why This Matters Now
Escalating state-sponsored cyber espionage campaigns against critical government and defense sectors highlight the urgent need for improved network visibility, segmentation, and endpoint security. As attacks become more persistent and evasive, adopting zero trust models and comprehensive compliance with data protection frameworks is essential to prevent similar incidents.
Attack Path Analysis
Salt Typhoon, a China-backed APT, initially compromised the US National Guard’s cloud environment, likely via credential abuse or unpatched vulnerability. The attackers escalated their cloud privileges to gain broader access, then moved laterally across workloads and services using east-west techniques. They established persistent command and control channels to manage operations and evade detection. Sensitive data was exfiltrated through covert or unmonitored egress paths. Finally, the group maintained long dwell time, causing intelligence exposure, with potential for business disruption or wider impact.
Kill Chain Progression
Initial Compromise
Description
The threat actor gained unauthorized access to the cloud environment, likely through stolen credentials or exploitation of a public-facing service.
Related CVEs
CVE-2023-20198
CVSS 10A vulnerability in the web UI feature of Cisco IOS XE Software allows an unauthenticated, remote attacker to create an account with privilege level 15 access.
Affected Products:
Cisco IOS XE – 16.9.1 and later
Exploit Status:
exploited in the wildCVE-2023-20273
CVSS 7.2A vulnerability in the web UI feature of Cisco IOS XE Software allows an authenticated, remote attacker to inject arbitrary commands with root privileges.
Affected Products:
Cisco IOS XE – 16.9.1 and later
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Exploit Public-Facing Application
Command and Scripting Interpreter
Remote Services
Application Layer Protocol
Phishing
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Account Management
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (EU Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA ZTMM 2.0 – Strong Authentication Enforcement
Control ID: Identity Pillar - Authentication
NIS2 Directive – Incident Handling and Response
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct target of Salt Typhoon APT with National Guard compromise exposing critical defense infrastructure, requiring enhanced zero trust segmentation and encrypted traffic monitoring.
Defense/Space
State-sponsored attacks on military systems demand immediate implementation of east-west traffic security, threat detection capabilities, and secure hybrid connectivity for classified operations.
Telecommunications
Critical infrastructure vulnerability to Chinese APT groups requires strengthened egress security, multicloud visibility controls, and inline IPS protection against lateral movement attacks.
Information Technology/IT
High-risk sector needing comprehensive cloud native security fabric deployment, kubernetes security hardening, and enhanced anomaly detection to prevent prolonged state-sponsored infiltrations.
Sources
- China-Backed Salt Typhoon Hacks US National Guard for Nearly a Yearhttps://www.darkreading.com/cyberattacks-data-breaches/salt-typhoon-hacks-us-national-guardVerified
- Salt Typhoon Exploits Cisco Devices in Telco Infrastructurehttps://www.darkreading.com/cyberattacks-data-breaches/salt-typhoon-exploits-cisco-devices-telco-infrastructure/Verified
- People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detectionhttps://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144aVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive Zero Trust controls—such as network segmentation, east-west inspection, granular egress enforcement, and real-time anomaly detection—would have constrained Salt Typhoon’s ability to move laterally, exfiltrate data, and operate undetected for months. CNSF-aligned capabilities deliver multi-layered defenses to disrupt state-sponsored APT kill chains at every stage.
Control: Cloud Firewall (ACF)
Mitigation: Limits exposure of public-facing cloud services through centralized, AI-driven detection and policy enforcement.
Control: Zero Trust Segmentation
Mitigation: Prevents privilege escalation across workloads with least-privilege, identity-based segmentation policies.
Control: East-West Traffic Security
Mitigation: Detects and blocks unauthorized lateral movement inside the cloud environment.
Control: Inline IPS (Suricata)
Mitigation: Detects and blocks known threat signatures and suspicious C2 behaviors in real time.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unsanctioned outbound traffic, preventing data exfiltration to unauthorized destinations.
Enables rapid detection of anomalies and suspicious activities, minimizing dwell time and operational impact.
Impact at a Glance
Affected Business Functions
- Military Operations
- Personnel Management
- Logistics
Estimated downtime: 30 days
Estimated loss: $5,000,000
Potential exposure of sensitive military personnel records, operational plans, and logistics data.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce granular Zero Trust segmentation to strictly limit lateral movement and privilege escalation opportunities
- • Deploy distributed, real-time east-west and egress inspection to detect and block command and control and exfiltration attempts
- • Centralize policy management and observability across all cloud and hybrid environments for full situational awareness
- • Implement cloud-native inline IPS to proactively stop known exploits, malware, and covert attacker behaviors
- • Continuously baseline and monitor cloud activities for anomalies, rapidly responding to suspicious or unauthorized actions



