Executive Summary
In early 2024, a cyber espionage campaign orchestrated by the China-linked Salt Typhoon group targeted forgotten and unpatched network perimeter devices, such as out-of-support routers, VPNs, and firewalls, across both public and private sector organizations in the U.S. and allied nations. Adversaries leveraged advanced "living off the land" tactics, establishing persistent access by exploiting technical debt and overlooked legacy hardware—bypassing hardened endpoint defenses and moving laterally within affected networks. Operational impacts included exposure of sensitive credentials, long-term surveillance risks, and significant challenges in incident detection and response due to the stealthy nature of the attacks.
This incident highlights a surge in sophisticated nation-state threats adapting to improved endpoint security by targeting unmanaged infrastructure. The campaign underscores the urgency for organizations to reassess asset inventories, prioritize decommissioning of end-of-life devices, and deploy proactive detection strategies, as similar tactics are increasingly observed across multiple state-sponsored and ransomware actors.
Why This Matters Now
Rapid shifts in adversary tactics are driving attackers toward vulnerable, under-managed network devices—areas often excluded from modern security programs. With end-of-life hardware now a top target for nation-state espionage, organizations must urgently implement proactive cyber resilience measures to mitigate persistent, high-impact threats.
Attack Path Analysis
Adversaries exploited unpatched and end-of-life perimeter network devices, gaining an initial foothold via exposed vulnerabilities. Through credential theft or exploiting configuration weaknesses, attackers escalated privileges to move deeper within the environment. Lateral movement across east-west traffic allowed the threat to access other network segments and workloads, leveraging stealthy tactics to avoid detection. Persistent command and control channels were established via covert outbound connections and living-off-the-land techniques. Sensitive data was exfiltrated over encrypted or disguised network flows. Ultimately, the attackers achieved long-term espionage objectives, maintaining persistence and undermining organizational resilience.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited vulnerabilities in unpatched, end-of-life network perimeter devices to gain an initial foothold.
Related CVEs
CVE-2024-21887
CVSS 9.8A command injection vulnerability in Ivanti Connect Secure and Policy Secure allows unauthenticated remote attackers to execute arbitrary commands.
Affected Products:
Ivanti Connect Secure – 9.x, 10.x
Ivanti Policy Secure – 9.x, 10.x
Exploit Status:
exploited in the wildCVE-2024-3400
CVSS 9.8An OS command injection vulnerability in Palo Alto Networks PAN-OS allows remote attackers to execute arbitrary code.
Affected Products:
Palo Alto Networks PAN-OS – < 10.2.3
Exploit Status:
exploited in the wildCVE-2023-20198
CVSS 10A privilege escalation vulnerability in Cisco IOS XE allows unauthenticated remote attackers to gain administrative control.
Affected Products:
Cisco IOS XE – 16.x, 17.x
Exploit Status:
exploited in the wildCVE-2023-20273
CVSS 9.8A command injection vulnerability in Cisco IOS XE allows remote attackers to execute arbitrary commands.
Affected Products:
Cisco IOS XE – 16.x, 17.x
Exploit Status:
exploited in the wildCVE-2018-0171
CVSS 9.8A remote code execution vulnerability in Cisco IOS and IOS XE Smart Install allows unauthenticated remote attackers to execute arbitrary code.
Affected Products:
Cisco IOS – 12.x, 15.x
Cisco IOS XE – 16.x
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Remote Services
Command and Scripting Interpreter
PowerShell
Impair Defenses
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Continuous Asset Inventory and Lifecycle Management
Control ID: Asset Management
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Nation-state espionage campaigns like Salt Typhoon directly target telecom infrastructure, exploiting unpatched network devices for credential theft and long-term persistence establishment.
Government Administration
Critical vulnerability to sophisticated APT groups using living-off-the-land tactics against forgotten network perimeter devices, compromising national security and sensitive operations.
Financial Services
End-of-life network devices create attack vectors for nation-state actors seeking financial data exfiltration through unencrypted traffic and compromised VPN infrastructure.
Health Care / Life Sciences
Technical debt in network perimeter security exposes patient data to advanced persistent threats exploiting forgotten routers and firewalls for covert operations.
Sources
- Shifting from reactive to proactive: Cyber resilience amid nation-state espionagehttps://cyberscoop.com/proactive-cyber-defense-forgotten-devices-op-ed/Verified
- GreyNoise Observes Active Exploitation of Cisco Vulnerabilities Tied to Salt Typhoon Attackshttps://www.greynoise.io/blog/greynoise-observes-active-exploitation-of-cisco-vulnerabilities-tied-to-salt-typhoon-attacksVerified
- Breaking Down Salt Typhoon | Armishttps://www.armis.com/threat-alert/breaking-down-salt-typhoon/Verified
- U.S. And Allies Declare Salt Typhoon Hack A National Defense Crisishttps://www.forbes.com/sites/emilsayegh/2025/08/30/us-and-allies-declare-salt-typhoon-hack-a-national-defense-crisis/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, microsegmentation, east-west traffic controls, egress policy enforcement, and adaptive threat detection provided by CNSF-aligned controls could have sharply reduced opportunities for attacker privilege escalation, lateral movement, and covert data exfiltration. Rigorous visibility, encrypted traffic protection, and runtime anomaly detection would have alerted defenders to abnormal device behaviors and blocked persistence attempts.
Control: Cloud Firewall (ACF)
Mitigation: Blocked unauthorized inbound access to vulnerable devices.
Control: Zero Trust Segmentation
Mitigation: Limited privilege escalation through identity-aware policy boundaries.
Control: East-West Traffic Security
Mitigation: Blocked or detected unauthorized lateral movement across cloud and hybrid networks.
Control: Egress Security & Policy Enforcement
Mitigation: Prevented unauthorized or anomalous outbound connections for C2.
Control: Encrypted Traffic (HPE) & Inline IPS (Suricata)
Mitigation: Detected and blocked unauthorized data exfiltration attempts.
Continuously detected abnormal behaviors and initiated incident response.
Impact at a Glance
Affected Business Functions
- Telecommunications
- Government Operations
- Military Communications
Estimated downtime: 30 days
Estimated loss: $50,000,000
Unauthorized access to sensitive communications, including metadata and content of calls and messages, affecting over a million users, including high-profile individuals and government officials.
Recommended Actions
Key Takeaways & Next Steps
- • Conduct a systematic inventory and decommission all end-of-life and unpatched network devices.
- • Deploy Zero Trust segmentation and microsegmentation to isolate workloads and minimize lateral movement exposure.
- • Enforce robust egress filtering and outbound policy controls to prevent unauthorized C2 and data exfiltration.
- • Integrate continuous threat detection and anomaly response to rapidly identify abnormal device or network activity.
- • Ensure all sensitive data in transit is encrypted at line rate, and monitor encrypted flows for possible misuse.



