A newly released joint advisory from the Canadian Centre for Cyber Security and the Federal Bureau of Investigation (FBI) has revealed that Salt Typhoon, a cyber-espionage group with suspected ties to China, exploited a critical Cisco vulnerability to breach the internal network of a Canadian telecommunications provider earlier this year.

The group leveraged CVE-2023-20198, a zero-day vulnerability in Cisco IOS XE software, to gain initial access and establish a covert communication channel that allowed them to exfiltrate sensitive data. The activity was discovered in mid-February 2025, but likely traces back to reconnaissance that began months earlier.


🕷️ Who is Salt Typhoon?

Salt Typhoon—also tracked as Earth Estries and UNC2286—has been linked to previous espionage campaigns targeting telecom and internet infrastructure across North America, Europe, and Africa. The group is reportedly affiliated with the Chinese Ministry of State Security (MSS) and specializes in advanced persistent threat (APT) operations.

According to cybersecurity researchers, Salt Typhoon distinguishes itself through its stealth, multi-stage intrusion techniques, and custom malware implants tailored for infrastructure environments.


🧰 The Exploit: Cisco IOS XE Vulnerability

The attack began with the exploitation of a previously disclosed vulnerability, CVE-2023-20198, which allows unauthenticated remote code execution on affected Cisco devices. While Cisco had issued a patch in late 2023, the impacted Canadian telecom firm had not yet applied the fix, making it a prime target.

Once inside, Salt Typhoon operators exfiltrated configuration files from at least three network devices, which likely included sensitive routing and administrative data. They also established a GRE (Generic Routing Encapsulation) tunnel, enabling them to redirect internal network traffic to infrastructure under their control.

This type of attack enables persistent access to internal systems while making detection by traditional intrusion systems extremely difficult.


🌐 Sector-Wide Threat

Although this specific breach targeted a Canadian telecom firm, the advisory warns that the technique and vulnerability used are applicable across various sectors, including:

  • Energy
  • Finance
  • Government agencies
  • Critical infrastructure

“Organizations that utilize Cisco IOS XE software should immediately assess their exposure,” the advisory stated, “and investigate signs of unauthorized GRE tunnels or unusual configuration changes.”


🌍 A Global Campaign

Salt Typhoon’s activities extend beyond Canada. Previously, the group has been linked to similar intrusions in:

  • The United States: Telecommunications companies and internet backbone providers
  • South Africa: State-owned telecom services
  • Italy: Government-managed infrastructure and private data carriers

In each case, the group has used a combination of zero-day exploits, social engineering, and custom backdoors to maintain prolonged access and extract intelligence of strategic value.

Security researchers believe the threat group’s operations are geopolitically motivated, often aligning with China’s broader intelligence-gathering and strategic initiatives.


🛡️ Recommendations for Organizations

In response to this growing threat, cybersecurity agencies across North America urge all organizations—especially those managing networking equipment—to adopt a layered defense strategy.

Recommended actions include:

  1. Patch Immediately – Apply all Cisco security updates, especially for IOS XE platforms.
  2. Audit Network Logs – Investigate configuration changes and search for unauthorized GRE tunnels.
  3. Limit External Access – Restrict administrative interfaces from public internet exposure.
  4. Segment Networks – Use VLANs and firewalls to limit the blast radius of compromised devices.
  5. Enable MFA – Apply multi-factor authentication for all network device login portals.
  6. Conduct Red Team Drills – Simulate Salt Typhoon’s tactics to improve detection and response readiness.

🔚 Final Word

This incident is a stark reminder that even well-established infrastructure providers are vulnerable if patch management and network monitoring are not prioritized. With China-linked threat actors continuing to exploit overlooked vulnerabilities for strategic gain, cybersecurity readiness has become a national priority.

Organizations across all sectors must recognize that sophisticated APT groups like Salt Typhoon are no longer targeting just governments—they are targeting the digital arteries of modern society.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *