Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
Nation-State Intrusions into Telecom Infrastructure via SS7 (TL-2026-2649) is a high-severity advanced persistent threat campaign scored CVSS 10, first published 2026-09-25. It is attributed to Salt Typhoon - G1045 (China) with high confidence, affects Cisco IOS XE Software (Web UI feature), references 6 CVEs (CVE-2023-20198, CVE-2023-20273, CVE-2023-46805), maps to 19 MITRE ATT&CK techniques (T1021.004, T1027, T1040), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-2649
- Threat ID
- TL-2026-2649
- Severity
- HIGH
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-09-25
- Last reviewed
- 2026-09-25
- Attribution
- Salt Typhoon - G1045
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- telecoms, critical infrastructure, government administration
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Nation-State Intrusions into Telecom Infrastructure via SS7
Malware and tooling: cmd1, STOWAWAY
PRC state-sponsored actors (Salt Typhoon and related trackers) have compromised large backbone routers of major telecommunications providers since at least 2021, achieving persistent, wiretap-equivalent access via known edge-device vulnerabilities (Cisco IOS XE, Ivanti Connect Secure, Palo Alto PAN-OS), GRE/IPsec tunnel persistence, and credential harvesting from TACACS+/RADIUS traffic. The same campaign surface includes decades-old SS7/Diameter signaling weaknesses and BGP route-hijacking techniques (2010 China Telecom incident) that are invisible to endpoint EDR. Joint CISA/NSA/FBI advisory AA25-239A (27 Aug 2025) documents the router-compromise playbook; exploitation uses known CVEs, not zero-days.
How Nation-State Intrusions into Telecom Infrastructure via SS7 works
This campaign spans three complementary attack surfaces of the global telecommunications infrastructure: SS7/Diameter signaling, BGP route propagation, and the compromise of provider edge and backbone routing devices by PRC state-sponsored actors.
ROUTER COMPROMISE (AA25-239A). The joint advisory co-sealed by NSA, CISA, FBI, DC3, ASD (ACSC), Canadian Cyber Centre, NCSC-NZ and NCSC-UK documents APT actors observed globally since at least 2021 targeting large backbone routers of major telecom providers as well as provider edge and customer edge routers. Initial access was achieved exclusively through known, publicly disclosed vulnerabilities - exploitation of zero-days has not been observed - including CVE-2023-20198/CVE-2023-20273 (Cisco IOS XE Web UI; unauthenticated privilege escalation chained with post-auth root command injection), CVE-2023-46805/CVE-2024-21887 (Ivanti Connect Secure and Policy Secure; authentication bypass chained with command injection), CVE-2024-3400 (Palo Alto PAN-OS GlobalProtect; unauthenticated command injection with root-level code execution) and CVE-2018-0171 (Cisco IOS/IOS XE Smart Install). Once on a device, the actors created unauthorized local accounts (including a sudo-privileged user named 'cisco'), inserted SSH keys, deployed Cisco Guest Shell containers to stage tooling, modified ACLs (commonly 'access-list 20'), redirected TACACS+ servers to actor-controlled IPs, and used non-standard ports (SSH on 22x22/xxx22 patterns, HTTP on 18xxx, a backdoored sshd_operns on TCP/57722 on IOS XR) to evade detection. Persistence and covert channels were built with tunnels over GRE, multipoint GRE (mGRE) and IPsec, obscuring source IPs in logs. Collection focused on network-device credentials and traffic: native PCAP capture (including Cisco Embedded Packet Capture) of TACACS+/RADIUS traffic on TCP/49, SPAN/RSPAN/ERSPAN traffic mirroring, MIB/configuration dumping (e.g. T1602.002), and brute-forcing Cisco Type 5 and Type 7 password hashes. Custom Golang SFTP clients (cmd1, cmd3, new2, sft) moved encrypted archives to staging hosts, STOWAWAY provided multi-hop SOCKS5/HTTP proxy pivoting, and data was exfiltrated to China via GRE and MPLS tunnels, including over ISP peering connections.
SS7/DIAMETER SIGNALING. SS7 underpins 2G/3G SMS, phone services and international roaming with no built-in mechanism to verify the origin of signaling requests: any node with signaling access can send Mobile Application Part (MAP) queries to locate a subscriber or redirect SMS. Documented consequences include location tracking, interception of voice traffic and MFA keys, and spies using SS7 as a delivery vector. 4G/5G migration does not eliminate the problem - Diameter has its own location-tracking weaknesses and 4G/5G users can be downgraded to SS7 while roaming. A 2017 DHS assessment reportedly concluded all U.S. carriers are vulnerable to SS7 and Diameter exploits, with Russia, China, Israel and Iran named as primary countries exploiting U.S. subscribers via third-country telecom assets; Cyble's dark-web research confirms SS7/Diameter exploits and services are still routinely traded on underground forums.
BGP ROUTE HIJACKING. BGP offers no intrinsic way to verify route origination: if a network announces a prefix it does not own (or a more specific slice), neighbors often accept it and redirect traffic. On 8 April 2010, China Telecom advertised erroneous routes for roughly 18 minutes, pulling traffic for approximately 15 percent of internet destinations - including U.S. government and military sites - through Chinese servers, per the U.S.-China Economic and Security Review Commission's 2010 report to Congress (FCC DOC-402579A1). In 2024 the FCC proposed requiring broadband providers to build BGP security plans based on RPKI, with the nine largest carriers filing confidential plans and publishing quarterly progress.
WHY DETECTION LAGS. SS7 abuse resembles normal roaming traffic, a hijacked prefix resembles an ordinary route update, and a rogue GRE tunnel resembles legitimate provisioning - none of it runs on an endpoint where EDR can observe it. By the time anomalous activity appears internally, the attacker has usually already mapped the network and begun lateral movement. Mitigation therefore centers on signaling firewalls (SS7/Diameter), routing-origin validation (ROAs + RPKI), patching the listed CVEs, auditing tunnels/mirror sessions/AAA configs against an approved baseline, management-plane isolation, and monitoring activity outside the perimeter.
MITRE ATT&CK techniques used in TL-2026-2649
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal
Credential Access
T1040 Network Sniffing; T1110.002 Password Cracking
Exfiltration
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Execution
Command and Control
T1090.003 Multi-hop Proxy; T1095 Non-Application Layer Protocol; T1571 Non-Standard Port; T1572 Protocol Tunneling
Persistence
T1098.004 SSH Authorized Keys; T1136.001 Local Account; T1543.005 Container Service
Initial Access
T1190 Exploit Public-Facing Application; T1199 Trusted Relationship
Resource Development
Collection
T1602.002 Network Device Configuration Dump
execution
Affected products and versions in Nation-State Intrusions into Telecom Infrastructure via SS7
- Cisco — IOS XE Software (Web UI feature)
Vulnerable versions: 16.1.1 through 17.11.99SW
Fixed in: 16.12.10a; 17.3.8a; 17.6.6a; 17.9.4a - Cisco — IOS / IOS XE (Smart Install)
Vulnerable versions: Smart Install-enabled IOS/IOS XE devices
Fixed in: Disable protocol or upgrade per vendor advisory - Ivanti — Connect Secure and Policy Secure
Vulnerable versions: 9.x up to 9.1R18; 22.x up to 22.6R2 (ICS) / 22.6R1 (IPS)
Fixed in: 9.1R18+; 22.6R2+ (ICS); 22.6R1+ (IPS) - Palo Alto Networks — PAN-OS (GlobalProtect portal/gateway)
Vulnerable versions: 10.2.x < 10.2.9-h1; 11.0.x < 11.0.4-h1; 11.1.x < 11.1.2-h3
Fixed in: 10.2.9-h1; 11.0.4-h1; 11.1.2-h3
Remediation for Nation-State Intrusions into Telecom Infrastructure via SS7
Patches
- Cisco IOS XE Web UI: apply fixed releases 16.12.10a, 17.3.8a, 17.6.6a, 17.9.4a
- Ivanti Connect Secure/Policy Secure: upgrade to 9.1R18/22.6R2 or later (CVE-2024-21887 chain)
- PAN-OS: upgrade GlobalProtect-enabled firewalls to 10.2.9-h1, 11.0.4-h1, 11.1.2-h3 or later
Immediate actions
- Patch all CVE-2023-20198, CVE-2023-20273, CVE-2023-46805, CVE-2024-21887, CVE-2024-3400 and CVE-2018-0171 exposure, prioritizing the CISA KEV catalog, then audit devices that were exposed for indicators of compromise before patching
- Pull device configurations and compare against authorized baselines; audit ACLs, local accounts, SSH keys, routing tables, SNMPv3 settings and PCAP/mirror session definitions
- Block known advisory IOCs at the perimeter and implement egress filtering for unexpected tunnels at peering points
Workarounds
- Disable the Cisco IOS XE web UI feature where not business-required ('no ip http server')
- Disable Cisco Smart Install (no vstack / smart-install disable)
- Delete default IKE policies; use DH Group 16/20 with AES-256 and SHA-384 per CNSSP 15
- Restrict SNMP writes, monitor SNMP SETs, and enforce strict eBGP filtering with maximum-prefix limits
Longer-term hardening
- Isolate management planes: dedicated out-of-band management network or management VRF with no data-plane route leakage, CoPP with default-deny management ACLs
- Deploy SS7 and Diameter firewalls and vet Global Title / roaming partners strictly
- Publish Route Origin Authorizations (ROAs) and enforce RPKI origin validation on eBGP sessions
- Disable Smart Install, Guest Shell ('guestshell disable', 'no iox') and unused web interfaces; SSHv2 only, SNMPv3 with authPriv and VACM views, AAA command accounting
- Migrate from Type 5/Type 7 password hashes to Type 8 / Type 6 key encryption
- Centralized immutable logging off-device; do not rely on device syslog alone
CVEs associated with Nation-State Intrusions into Telecom Infrastructure via SS7
CVE-2023-20198, CVE-2023-20273, CVE-2023-46805, CVE-2024-21887, CVE-2024-3400, CVE-2018-0171
Weaknesses (CWE) in Nation-State Intrusions into Telecom Infrastructure via SS7
CWE-77, CWE-420, CWE-20
Timeline of Nation-State Intrusions into Telecom Infrastructure via SS7
- China Telecom advertises erroneous BGP routes for ~18 minutes, pulling traffic for roughly 15 percent of internet destinations - including U.S. government and military sites - through Chinese servers (U.S.-China Economic and Security Review Commission 2010 report).
- DHS assessment reported to Congress: all U.S. carriers are vulnerable to SS7 and Diameter exploits; Russia, China, Israel and Iran named as primary countries exploiting U.S. subscribers via third-country telecom assets (year as reported by Cyble).
- Malicious operations by the PRC-sponsored cluster now tracked as Salt Typhoon / Operator Panda / UNC5807 observed globally 'since at least 2021' per joint advisory AA25-239A.
- Cisco discloses active in-the-wild exploitation of CVE-2023-20198 (IOS XE Web UI privilege escalation, CVSS 10.0) chained with CVE-2023-20273 for root-level code execution; actors create a privilege-15 local account and write an implant to the file system. CISA adds both to KEV.
- Exploitation of Ivanti Connect Secure/Policy Secure CVE-2023-46805 + CVE-2024-21887 (auth bypass chained with command injection) begins; CISA adds CVE-2024-21887 to KEV (due 2024-01-22); NVD publishes 2024-01-12.
- CVE-2024-3400 (PAN-OS GlobalProtect unauthenticated command injection, CVSS 10.0) disclosed after discovery in production use as a zero-day; CISA adds to KEV same day. Persistence surviving resets/upgrades later publicly demonstrated.
- WSJ reports China-linked hackers (Salt Typhoon) breached U.S. internet providers in the first major public disclosure of the telecommunications intrusions.
- CNN reports Chinese government-linked hackers infiltrated AT&T, Verizon and Lumen and may have accessed wiretap warrant requests used for court-approved law-enforcement surveillance.
- FCC confirms PRC state-sponsored actors infiltrated at least eight U.S. communications companies and proposes a Declaratory Ruling that CALEA Section 105 obligates carriers to secure networks against unlawful interception, plus an NPRM requiring annual cybersecurity certifications.
- U.S. sanctions a PRC-based individual and cybersecurity company for their alleged role in the Salt Typhoon intrusions.
- Joint advisory AA25-239A (NSA, CISA, FBI, DC3, ACSC, Canadian Cyber Centre, NCSC-NZ, NCSC-UK and 9 additional international partners) published documenting PRC state-sponsored compromise of telecom backbone routers, tunnels (GRE/mGRE/IPsec), Guest Shell staging, TACACS+/RADIUS credential capture, and IOCs.
- AA25-239A revised to v1.1 correcting an IP and removing two indicators and a Japan NCO name.
- Cyble publishes its survey of the telecom attack surface ('Inside the Telecom Attack Surface'), documenting SS7/Diameter abuse, the 2010 China Telecom BGP incident, the AA25-239A router-compromise campaign, underground trading of signaling exploits, and detection gaps.
Sources cited for Nation-State Intrusions into Telecom Infrastructure via SS7
- Inside the Telecom Attack Surface: SS7, BGP Hijacking, and the Technical Reality of Nation-State Intrusions (Cyble)
- Joint Advisory AA25-239A: PRC State-Sponsored Actors Compromise and Maintain Persistence in U.S. Telecommunications Provider Networks
- CISA Known Exploited Vulnerabilities Catalog
- NVD Entry CVE-2023-20198 (Cisco IOS XE Web UI Privilege Escalation)
- NVD Entry CVE-2024-21887 (Ivanti Connect Secure / Policy Secure Command Injection)
- NVD Entry CVE-2024-3400 (Palo Alto PAN-OS GlobalProtect Command Injection)
- Cisco Security Advisory: Cisco IOS XE Software Web UI Privilege Escalation Vulnerability (cisco-sa-iosxe-webui-privesc-j22SaA4z)
- Palo Alto Networks Security Advisory: PAN-OS GlobalProtect CVE-2024-3400
- Volexity: Zero-Day Exploitation of Unauthenticated Remote Code Execution in GlobalProtect (CVE-2024-3400)
- Unit 42: CVE-2024-3400 Exploitation Analysis
- FCC Fact Sheet: Declaratory Ruling and NPRM on Carrier Cybersecurity (DOC-408015A1)
- U.S.-China Economic and Security Review Commission 2010 Report to Congress (China Telecom route hijack)
- WSJ: China-Linked Hackers Breach U.S. Internet Providers
- CNN: Chinese hackers infiltrated major U.S. telecom firms, potentially accessing wiretap warrant requests
More in apt
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and DCSync to Compromise Russian Active Directory
- North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via Fake Job Interviews and npm/PyPI/Go/Rust Supply-Chain Packages
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle Malware
Detection coverage for TL-2026-2649
As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2649 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.