Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagetelecommunications-sector-threatgovernment-diplomatic-threatperimeter-device-exposure

Salt Typhoon Cyber Espionage Campaign Targeting U.S. Telecom and Government Networks

Updated 3mo agoFirst seen Oct 24, 20252 sources

Salt Typhoon, a threat group linked to the People’s Republic of China, conducted a multiyear cyber espionage campaign targeting major U.S. telecom providers such as Verizon, AT&T, and T-Mobile, compromising the data of hundreds of millions of users. The campaign is considered by U.S. officials to be the most significant cyber espionage operation in history, with attackers gaining access to sensitive information including call logs, unencrypted texts, and audio from high-ranking political figures, as well as targeting law enforcement intercept backdoors and military networks. The group’s activities have raised concerns about potential election interference, political blackmail, and threats to national security.

Salt Typhoon exploited unpatched, end-of-life, and forgotten network perimeter devices—such as routers, VPNs, and firewalls—using sophisticated “living off the land” tactics to establish long-term persistence and evade detection. The attackers stole administrator credentials, network traffic diagrams, and personal information from military and state cybersecurity personnel, using this intelligence to fuel further intrusions. The campaign highlights the urgent need for organizations to address technical debt and proactively secure legacy infrastructure, as reactive patching cannot undo compromises on already breached devices.

Share:
Salt Typhoon Cyber Espionage Campaign Targeting U.S. Telecom and Government Networks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Oct 24, 20258mo ago

Commentary urges proactive defense for forgotten devices after espionage concerns

A subsequent October 2025 reference emphasized shifting from reactive security to proactive cyber defense, particularly for neglected or forgotten devices exposed during nation-state espionage activity. This reflects an evolution in the public response to the Salt Typhoon-related threat environment.

Oct 22, 20258mo ago

Salt Typhoon campaign prompts calls to reconfigure U.S. cyber strategy

By October 2025, analysis of the Salt Typhoon espionage activity had driven public calls to rethink U.S. cyber strategy and resilience against nation-state intrusions. The references frame the campaign as a significant enough development to spur debate over proactive defense and protection of overlooked devices.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.