Nation-state hackers backed by Beijing have successfully infiltrated several U.S. internet service providers (ISPs) in a cyber espionage operation designed to extract sensitive information, according to a report by The Wall Street Journal on Wednesday.
The malicious activity has been attributed to a group tracked by Microsoft under the name Salt Typhoon, also known by aliases like FamousSparrow and GhostEmperor.
Investigators are examining whether the attackers gained access to Cisco Systems routers, which are critical components responsible for routing much of the internet's traffic, according to sources familiar with the investigation.
The objective of these attacks is to secure persistent access within the targeted networks, allowing the cybercriminals to harvest sensitive data or execute more devastating cyberattacks in the future.
GhostEmperor first surfaced publicly in October 2021 when Russian cybersecurity firm Kaspersky disclosed a long-running, stealthy campaign primarily targeting Southeast Asian nations. This campaign involved deploying a sophisticated rootkit named Demodex, and the targets included high-profile entities in countries such as Malaysia, Thailand, Vietnam, and Indonesia. Other outlier targets were located in Egypt, Ethiopia, and Afghanistan.
More recently, in July 2024, cybersecurity company Sygnia revealed that an unnamed client was compromised by Salt Typhoon in 2023. The attack involved infiltrating one of the client’s business partner's networks, where multiple servers, workstations, and users were compromised. Sygnia noted that a variant of the Demodex rootkit was used to communicate with command-and-control servers operated by the attackers.
This breach follows closely on the heels of another U.S. government action, which successfully disrupted a 260,000-device botnet called Raptor Train. This botnet was controlled by Flax Typhoon, another hacking group linked to Beijing.
The increasing number of cyberattacks targeting U.S. telecom, ISPs, and other critical infrastructure sectors highlights the persistent and evolving threat posed by Chinese state-sponsored actors.