The Containment Era is here. →Explore

Executive Summary

Between 2021 and 2023, advanced Chinese threat actors known as Salt Typhoon and Volt Typhoon conducted highly covert cyber intrusions targeting U.S. telecommunications networks and critical infrastructure sectors. These groups utilized advanced tactics such as "living off the land," abusing legitimate administrative tools, and blending into east-west network traffic, making detection and remediation extremely challenging for defenders. Their primary objectives ranged from long-term espionage and persistent access to prepositioning for potential disruptive attacks in the event of geopolitical conflict. The hacks led federal agencies like the FBI and CISA to revise investigative methods, shifting to assume attackers may already be inside the network and forcing collaboration to uncover subtle anomalies rather than clear indicators.

This incident is indicative of a broader industry trend: state-backed actors increasingly focus on stealth, cloud environments, and edge devices, targeting managed service providers and exploiting blind spots in monitoring. Their evolving tactics closely align with growing regulatory and CISO concern for stronger east-west visibility, zero trust controls, and continuous threat hunting across hybrid cloud infrastructure.

Why This Matters Now

Nation-state attackers are shifting from noisy, opportunistic data theft to stealthy and persistent methods that evade traditional detection, targeting cloud and edge devices across critical sectors. This urgent threat demands organizations enhance their cloud visibility, enforce zero trust segmentation, and invest in anomaly detection to counter changing adversary strategies.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

These incidents highlighted insufficient east-west traffic monitoring, limited cloud and edge device visibility, and a lack of zero trust segmentation and anomaly detection across hybrid environments.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Comprehensive application of Zero Trust segmentation, east-west traffic controls, runtime network visibility, egress policy enforcement, and encrypted data-in-transit would have severely constrained or detected each stage of this attack, limiting both spread and impact within the cloud environment.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocked unauthorized access to exposed services at the perimeter.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limited lateral privilege abuse by enforcing least privilege and identity-based policy.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detected and/or blocked unauthorized workload-to-workload movement.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detected or blocked known bad payloads and suspicious outbound C2 patterns.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevented or alerted on unauthorized outbound data transfers.

Impact (Mitigations)

Detected abnormal activity, enabling rapid incident containment.

Impact at a Glance

Affected Business Functions

  • Telecommunications
  • Energy
  • Transportation
  • Water and Wastewater Systems
Operational Disruption

Estimated downtime: 10 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive configuration files, administrator credentials, and network diagrams, which could facilitate further intrusions and disruptions.

Recommended Actions

  • Enforce Zero Trust segmentation and microsegmentation across all cloud workloads, edge devices, and Kubernetes namespaces.
  • Implement robust east-west traffic monitoring and control with policy-based barriers for workload-to-workload and inter-region movement.
  • Deploy inline intrusion prevention and cloud firewall controls to detect and block unauthorized perimeter access and attempted C2 establishment.
  • Establish egress filtering and real-time policy enforcement to prevent unsanctioned data exfiltration and restrict outbound communications.
  • Continuously monitor for anomalous behaviors and establish automated response playbooks leveraging full-cloud visibility and baseline-driven detection.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image