Executive Summary
Between 2021 and 2023, advanced Chinese threat actors known as Salt Typhoon and Volt Typhoon conducted highly covert cyber intrusions targeting U.S. telecommunications networks and critical infrastructure sectors. These groups utilized advanced tactics such as "living off the land," abusing legitimate administrative tools, and blending into east-west network traffic, making detection and remediation extremely challenging for defenders. Their primary objectives ranged from long-term espionage and persistent access to prepositioning for potential disruptive attacks in the event of geopolitical conflict. The hacks led federal agencies like the FBI and CISA to revise investigative methods, shifting to assume attackers may already be inside the network and forcing collaboration to uncover subtle anomalies rather than clear indicators.
This incident is indicative of a broader industry trend: state-backed actors increasingly focus on stealth, cloud environments, and edge devices, targeting managed service providers and exploiting blind spots in monitoring. Their evolving tactics closely align with growing regulatory and CISO concern for stronger east-west visibility, zero trust controls, and continuous threat hunting across hybrid cloud infrastructure.
Why This Matters Now
Nation-state attackers are shifting from noisy, opportunistic data theft to stealthy and persistent methods that evade traditional detection, targeting cloud and edge devices across critical sectors. This urgent threat demands organizations enhance their cloud visibility, enforce zero trust segmentation, and invest in anomaly detection to counter changing adversary strategies.
Attack Path Analysis
The attackers initially compromised cloud or edge infrastructure by targeting exposed or vulnerable devices and services tied to VPN and remote management. Upon gaining an initial foothold, they used legitimate credentials or misconfigurations to escalate privileges within the cloud environment. Leveraging stealthy techniques, they moved laterally through internal cloud networks and workloads, making use of 'living off the land' methods to evade detection. The adversaries established command and control channels, often blending traffic with legitimate activity and using encrypted channels. Data exfiltration was carried out covertly through egress channels while minimizing artifacts. Ultimately, the attackers positioned themselves for disruptive impacts against critical infrastructure assets, potentially causing operational downtime or paving the way for destructive attacks.
Kill Chain Progression
Initial Compromise
Description
Exploited exposed VPN, edge devices, or cloud service misconfigurations to gain initial access to the network.
Related CVEs
CVE-2021-26855
CVSS 9.8A server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server allows an unauthenticated attacker to send arbitrary HTTP requests and authenticate as the Exchange server.
Affected Products:
Microsoft Exchange Server – 2013, 2016, 2019
Exploit Status:
exploited in the wildCVE-2022-3236
CVSS 9.8A code injection vulnerability in the User Portal and Webadmin components of Sophos Firewall allows remote code execution.
Affected Products:
Sophos Firewall – < 19.0.1
Exploit Status:
exploited in the wildCVE-2023-48788
CVSS 9.8A SQL injection vulnerability in FortiClient Enterprise Management Server (EMS) allows an unauthenticated attacker to execute arbitrary SQL queries.
Affected Products:
Fortinet FortiClient EMS – < 7.0.1
Exploit Status:
exploited in the wildCVE-2023-20198
CVSS 10A privilege escalation vulnerability in Cisco IOS XE allows an unauthenticated attacker to create an account with privilege level 15 access.
Affected Products:
Cisco IOS XE – 16.9.1, 16.9.2, 16.9.3
Exploit Status:
exploited in the wildCVE-2023-20273
CVSS 7.2A privilege escalation vulnerability in Cisco IOS XE allows an authenticated attacker to elevate privileges to level 15.
Affected Products:
Cisco IOS XE – 16.9.1, 16.9.2, 16.9.3
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Web Protocols
Exploit Public-Facing Application
Impair Defenses: Disable or Modify Tools
Exploitation of Remote Services
OS Credential Dumping
Remote Services: Remote Desktop Protocol
Indicator Removal on Host: File Deletion
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Implement Automated Audit Trails
Control ID: 10.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy and Monitoring
Control ID: 500.03, 500.14
DORA – ICT Risk Management & Monitoring
Control ID: Art. 8(2), Art. 10(1)
CISA ZTMM 2.0 – Continuous Monitoring Capabilities
Control ID: Visibility & Analytics
NIS2 Directive – Incident Detection and Response Capabilities
Control ID: Art. 21(2)(d), Art. 21(2)(f)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Salt Typhoon's massive telecommunications hack demonstrates APT groups' persistent access capabilities, requiring enhanced encrypted traffic monitoring and east-west segmentation defenses.
Government Administration
Chinese Typhoon groups' living-off-the-land techniques targeting critical infrastructure necessitate zero trust segmentation and improved anomaly detection for government networks.
Utilities
Volt Typhoon's critical infrastructure infiltration for potential Taiwan conflict disruption highlights urgent need for multicloud visibility and egress security controls.
Information Technology/IT
APT groups' shift to cloud targeting and edge device exploitation requires enhanced Kubernetes security, threat detection, and secure hybrid connectivity solutions.
Sources
- China’s ‘Typhoons’ changing the way FBI hunts sophisticated threatshttps://cyberscoop.com/chinas-typhoons-changing-the-way-fbi-hunts-sophisticated-threats/Verified
- Salt Typhoon: An Analysis of Vulnerabilities Exploited by this State-Sponsored Actorhttps://www.tenable.com/blog/salt-typhoon-an-analysis-of-vulnerabilities-exploited-by-this-state-sponsored-actorVerified
- Volt Typhoon targets US critical infrastructure with living-off-the-land techniqueshttps://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/Verified
- NSA says Volt Typhoon was 'not successful' at persisting in critical infrastructurehttps://www.techradar.com/pro/security/nsa-says-volt-typhoon-was-not-successful-at-persisting-in-critical-infrastructureVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive application of Zero Trust segmentation, east-west traffic controls, runtime network visibility, egress policy enforcement, and encrypted data-in-transit would have severely constrained or detected each stage of this attack, limiting both spread and impact within the cloud environment.
Control: Cloud Firewall (ACF)
Mitigation: Blocked unauthorized access to exposed services at the perimeter.
Control: Zero Trust Segmentation
Mitigation: Limited lateral privilege abuse by enforcing least privilege and identity-based policy.
Control: East-West Traffic Security
Mitigation: Detected and/or blocked unauthorized workload-to-workload movement.
Control: Inline IPS (Suricata)
Mitigation: Detected or blocked known bad payloads and suspicious outbound C2 patterns.
Control: Egress Security & Policy Enforcement
Mitigation: Prevented or alerted on unauthorized outbound data transfers.
Detected abnormal activity, enabling rapid incident containment.
Impact at a Glance
Affected Business Functions
- Telecommunications
- Energy
- Transportation
- Water and Wastewater Systems
Estimated downtime: 10 days
Estimated loss: $5,000,000
Potential exposure of sensitive configuration files, administrator credentials, and network diagrams, which could facilitate further intrusions and disruptions.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation and microsegmentation across all cloud workloads, edge devices, and Kubernetes namespaces.
- • Implement robust east-west traffic monitoring and control with policy-based barriers for workload-to-workload and inter-region movement.
- • Deploy inline intrusion prevention and cloud firewall controls to detect and block unauthorized perimeter access and attempted C2 establishment.
- • Establish egress filtering and real-time policy enforcement to prevent unsanctioned data exfiltration and restrict outbound communications.
- • Continuously monitor for anomalous behaviors and establish automated response playbooks leveraging full-cloud visibility and baseline-driven detection.



