Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)

Nation-State Intrusions into Telecom Infrastructure via SS7 (TL-2026-2649) is a high-severity advanced persistent threat campaign scored CVSS 10, first published 2026-09-25. It is attributed to Salt Typhoon - G1045 (China) with high confidence, affects Cisco IOS XE Software (Web UI feature), references 6 CVEs (CVE-2023-20198, CVE-2023-20273, CVE-2023-46805), maps to 19 MITRE ATT&CK techniques (T1021.004, T1027, T1040), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-2649

Threat ID
TL-2026-2649
Severity
HIGH
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
APT
First published
2026-09-25
Last reviewed
2026-09-25
Attribution
Salt Typhoon - G1045
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
telecoms, critical infrastructure, government administration
Target regions
Global
Detection rules
9
Indicators of compromise
22

Malware and tooling in Nation-State Intrusions into Telecom Infrastructure via SS7

Malware and tooling: cmd1, STOWAWAY

PRC state-sponsored actors (Salt Typhoon and related trackers) have compromised large backbone routers of major telecommunications providers since at least 2021, achieving persistent, wiretap-equivalent access via known edge-device vulnerabilities (Cisco IOS XE, Ivanti Connect Secure, Palo Alto PAN-OS), GRE/IPsec tunnel persistence, and credential harvesting from TACACS+/RADIUS traffic. The same campaign surface includes decades-old SS7/Diameter signaling weaknesses and BGP route-hijacking techniques (2010 China Telecom incident) that are invisible to endpoint EDR. Joint CISA/NSA/FBI advisory AA25-239A (27 Aug 2025) documents the router-compromise playbook; exploitation uses known CVEs, not zero-days.

How Nation-State Intrusions into Telecom Infrastructure via SS7 works

This campaign spans three complementary attack surfaces of the global telecommunications infrastructure: SS7/Diameter signaling, BGP route propagation, and the compromise of provider edge and backbone routing devices by PRC state-sponsored actors.

ROUTER COMPROMISE (AA25-239A). The joint advisory co-sealed by NSA, CISA, FBI, DC3, ASD (ACSC), Canadian Cyber Centre, NCSC-NZ and NCSC-UK documents APT actors observed globally since at least 2021 targeting large backbone routers of major telecom providers as well as provider edge and customer edge routers. Initial access was achieved exclusively through known, publicly disclosed vulnerabilities - exploitation of zero-days has not been observed - including CVE-2023-20198/CVE-2023-20273 (Cisco IOS XE Web UI; unauthenticated privilege escalation chained with post-auth root command injection), CVE-2023-46805/CVE-2024-21887 (Ivanti Connect Secure and Policy Secure; authentication bypass chained with command injection), CVE-2024-3400 (Palo Alto PAN-OS GlobalProtect; unauthenticated command injection with root-level code execution) and CVE-2018-0171 (Cisco IOS/IOS XE Smart Install). Once on a device, the actors created unauthorized local accounts (including a sudo-privileged user named 'cisco'), inserted SSH keys, deployed Cisco Guest Shell containers to stage tooling, modified ACLs (commonly 'access-list 20'), redirected TACACS+ servers to actor-controlled IPs, and used non-standard ports (SSH on 22x22/xxx22 patterns, HTTP on 18xxx, a backdoored sshd_operns on TCP/57722 on IOS XR) to evade detection. Persistence and covert channels were built with tunnels over GRE, multipoint GRE (mGRE) and IPsec, obscuring source IPs in logs. Collection focused on network-device credentials and traffic: native PCAP capture (including Cisco Embedded Packet Capture) of TACACS+/RADIUS traffic on TCP/49, SPAN/RSPAN/ERSPAN traffic mirroring, MIB/configuration dumping (e.g. T1602.002), and brute-forcing Cisco Type 5 and Type 7 password hashes. Custom Golang SFTP clients (cmd1, cmd3, new2, sft) moved encrypted archives to staging hosts, STOWAWAY provided multi-hop SOCKS5/HTTP proxy pivoting, and data was exfiltrated to China via GRE and MPLS tunnels, including over ISP peering connections.

SS7/DIAMETER SIGNALING. SS7 underpins 2G/3G SMS, phone services and international roaming with no built-in mechanism to verify the origin of signaling requests: any node with signaling access can send Mobile Application Part (MAP) queries to locate a subscriber or redirect SMS. Documented consequences include location tracking, interception of voice traffic and MFA keys, and spies using SS7 as a delivery vector. 4G/5G migration does not eliminate the problem - Diameter has its own location-tracking weaknesses and 4G/5G users can be downgraded to SS7 while roaming. A 2017 DHS assessment reportedly concluded all U.S. carriers are vulnerable to SS7 and Diameter exploits, with Russia, China, Israel and Iran named as primary countries exploiting U.S. subscribers via third-country telecom assets; Cyble's dark-web research confirms SS7/Diameter exploits and services are still routinely traded on underground forums.

BGP ROUTE HIJACKING. BGP offers no intrinsic way to verify route origination: if a network announces a prefix it does not own (or a more specific slice), neighbors often accept it and redirect traffic. On 8 April 2010, China Telecom advertised erroneous routes for roughly 18 minutes, pulling traffic for approximately 15 percent of internet destinations - including U.S. government and military sites - through Chinese servers, per the U.S.-China Economic and Security Review Commission's 2010 report to Congress (FCC DOC-402579A1). In 2024 the FCC proposed requiring broadband providers to build BGP security plans based on RPKI, with the nine largest carriers filing confidential plans and publishing quarterly progress.

WHY DETECTION LAGS. SS7 abuse resembles normal roaming traffic, a hijacked prefix resembles an ordinary route update, and a rogue GRE tunnel resembles legitimate provisioning - none of it runs on an endpoint where EDR can observe it. By the time anomalous activity appears internally, the attacker has usually already mapped the network and begun lateral movement. Mitigation therefore centers on signaling firewalls (SS7/Diameter), routing-origin validation (ROAs + RPKI), patching the listed CVEs, auditing tunnels/mirror sessions/AAA configs against an approved baseline, management-plane isolation, and monitoring activity outside the perimeter.

MITRE ATT&CK techniques used in TL-2026-2649

Lateral Movement

T1021.004 SSH

Defense Evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal

Credential Access

T1040 Network Sniffing; T1110.002 Password Cracking

Exfiltration

T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol

Execution

T1059.008 Network Device CLI

Command and Control

T1090.003 Multi-hop Proxy; T1095 Non-Application Layer Protocol; T1571 Non-Standard Port; T1572 Protocol Tunneling

Persistence

T1098.004 SSH Authorized Keys; T1136.001 Local Account; T1543.005 Container Service

Initial Access

T1190 Exploit Public-Facing Application; T1199 Trusted Relationship

Resource Development

T1584.008 Network Devices

Collection

T1602.002 Network Device Configuration Dump

execution

T1610 Deploy Container

Affected products and versions in Nation-State Intrusions into Telecom Infrastructure via SS7

  • Cisco — IOS XE Software (Web UI feature)
    Vulnerable versions: 16.1.1 through 17.11.99SW
    Fixed in: 16.12.10a; 17.3.8a; 17.6.6a; 17.9.4a
  • Cisco — IOS / IOS XE (Smart Install)
    Vulnerable versions: Smart Install-enabled IOS/IOS XE devices
    Fixed in: Disable protocol or upgrade per vendor advisory
  • Ivanti — Connect Secure and Policy Secure
    Vulnerable versions: 9.x up to 9.1R18; 22.x up to 22.6R2 (ICS) / 22.6R1 (IPS)
    Fixed in: 9.1R18+; 22.6R2+ (ICS); 22.6R1+ (IPS)
  • Palo Alto Networks — PAN-OS (GlobalProtect portal/gateway)
    Vulnerable versions: 10.2.x < 10.2.9-h1; 11.0.x < 11.0.4-h1; 11.1.x < 11.1.2-h3
    Fixed in: 10.2.9-h1; 11.0.4-h1; 11.1.2-h3

Remediation for Nation-State Intrusions into Telecom Infrastructure via SS7

Patches

  • Cisco IOS XE Web UI: apply fixed releases 16.12.10a, 17.3.8a, 17.6.6a, 17.9.4a
  • Ivanti Connect Secure/Policy Secure: upgrade to 9.1R18/22.6R2 or later (CVE-2024-21887 chain)
  • PAN-OS: upgrade GlobalProtect-enabled firewalls to 10.2.9-h1, 11.0.4-h1, 11.1.2-h3 or later

Immediate actions

  • Patch all CVE-2023-20198, CVE-2023-20273, CVE-2023-46805, CVE-2024-21887, CVE-2024-3400 and CVE-2018-0171 exposure, prioritizing the CISA KEV catalog, then audit devices that were exposed for indicators of compromise before patching
  • Pull device configurations and compare against authorized baselines; audit ACLs, local accounts, SSH keys, routing tables, SNMPv3 settings and PCAP/mirror session definitions
  • Block known advisory IOCs at the perimeter and implement egress filtering for unexpected tunnels at peering points

Workarounds

  • Disable the Cisco IOS XE web UI feature where not business-required ('no ip http server')
  • Disable Cisco Smart Install (no vstack / smart-install disable)
  • Delete default IKE policies; use DH Group 16/20 with AES-256 and SHA-384 per CNSSP 15
  • Restrict SNMP writes, monitor SNMP SETs, and enforce strict eBGP filtering with maximum-prefix limits

Longer-term hardening

  • Isolate management planes: dedicated out-of-band management network or management VRF with no data-plane route leakage, CoPP with default-deny management ACLs
  • Deploy SS7 and Diameter firewalls and vet Global Title / roaming partners strictly
  • Publish Route Origin Authorizations (ROAs) and enforce RPKI origin validation on eBGP sessions
  • Disable Smart Install, Guest Shell ('guestshell disable', 'no iox') and unused web interfaces; SSHv2 only, SNMPv3 with authPriv and VACM views, AAA command accounting
  • Migrate from Type 5/Type 7 password hashes to Type 8 / Type 6 key encryption
  • Centralized immutable logging off-device; do not rely on device syslog alone

CVEs associated with Nation-State Intrusions into Telecom Infrastructure via SS7

CVE-2023-20198, CVE-2023-20273, CVE-2023-46805, CVE-2024-21887, CVE-2024-3400, CVE-2018-0171

Weaknesses (CWE) in Nation-State Intrusions into Telecom Infrastructure via SS7

CWE-77, CWE-420, CWE-20

Timeline of Nation-State Intrusions into Telecom Infrastructure via SS7

  • China Telecom advertises erroneous BGP routes for ~18 minutes, pulling traffic for roughly 15 percent of internet destinations - including U.S. government and military sites - through Chinese servers (U.S.-China Economic and Security Review Commission 2010 report).
  • DHS assessment reported to Congress: all U.S. carriers are vulnerable to SS7 and Diameter exploits; Russia, China, Israel and Iran named as primary countries exploiting U.S. subscribers via third-country telecom assets (year as reported by Cyble).
  • Malicious operations by the PRC-sponsored cluster now tracked as Salt Typhoon / Operator Panda / UNC5807 observed globally 'since at least 2021' per joint advisory AA25-239A.
  • Cisco discloses active in-the-wild exploitation of CVE-2023-20198 (IOS XE Web UI privilege escalation, CVSS 10.0) chained with CVE-2023-20273 for root-level code execution; actors create a privilege-15 local account and write an implant to the file system. CISA adds both to KEV.
  • Exploitation of Ivanti Connect Secure/Policy Secure CVE-2023-46805 + CVE-2024-21887 (auth bypass chained with command injection) begins; CISA adds CVE-2024-21887 to KEV (due 2024-01-22); NVD publishes 2024-01-12.
  • CVE-2024-3400 (PAN-OS GlobalProtect unauthenticated command injection, CVSS 10.0) disclosed after discovery in production use as a zero-day; CISA adds to KEV same day. Persistence surviving resets/upgrades later publicly demonstrated.
  • WSJ reports China-linked hackers (Salt Typhoon) breached U.S. internet providers in the first major public disclosure of the telecommunications intrusions.
  • CNN reports Chinese government-linked hackers infiltrated AT&T, Verizon and Lumen and may have accessed wiretap warrant requests used for court-approved law-enforcement surveillance.
  • FCC confirms PRC state-sponsored actors infiltrated at least eight U.S. communications companies and proposes a Declaratory Ruling that CALEA Section 105 obligates carriers to secure networks against unlawful interception, plus an NPRM requiring annual cybersecurity certifications.
  • U.S. sanctions a PRC-based individual and cybersecurity company for their alleged role in the Salt Typhoon intrusions.
  • Joint advisory AA25-239A (NSA, CISA, FBI, DC3, ACSC, Canadian Cyber Centre, NCSC-NZ, NCSC-UK and 9 additional international partners) published documenting PRC state-sponsored compromise of telecom backbone routers, tunnels (GRE/mGRE/IPsec), Guest Shell staging, TACACS+/RADIUS credential capture, and IOCs.
  • AA25-239A revised to v1.1 correcting an IP and removing two indicators and a Japan NCO name.
  • Cyble publishes its survey of the telecom attack surface ('Inside the Telecom Attack Surface'), documenting SS7/Diameter abuse, the 2010 China Telecom BGP incident, the AA25-239A router-compromise campaign, underground trading of signaling exploits, and detection gaps.

Sources cited for Nation-State Intrusions into Telecom Infrastructure via SS7

More in apt

Detection coverage for TL-2026-2649

As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2649 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats