IoT cybersecurity news

China-backed Salt Typhoon Reportedly Targets ISPs, Sets “New Expectation”

A Chinese government-linked threat group has reportedly infiltrated critical US networks, this time focusing on internet service providers (ISPs) to gather sensitive data and potentially initiate cyberattacks. According to a Wednesday report from The Wall Street Journal, citing sources familiar with the matter, the groupโ€”identified as Salt Typhoonโ€”has gained access to the IT systems of several ISPs in recent months.

โ€œItโ€™s likely weโ€™re going to see more of these Typhoon variants,โ€ John Terrill, CISO of Phosphorus Cybersecurity, told Security Boulevard.

โ€œIn the past, the expectation for cybersecurity teams was to build defenses to the level of capabilities of the expected attacker, which was normally hacktivists and criminals. With the increasing amount of Typhoon activity across multiple industries, I think weโ€™re facing a new expectation that we may all have to start increasing our cybersecurity programs to account for nation-states.โ€

Could Salt Typhoon affect OT environments in other areas of infrastructure? At this point, Terrill tells Industrial Cyber, it’s too early to say.

โ€œAt the moment, Salt Typhoon is limited to internet service providers that could definitely be considered critical infrastructure. ISPs donโ€™t tend to have a lot of traditional OT environments but that doesnโ€™t mean those environments arenโ€™t being targeted. The same issues plaguing ISPs are plaguing companies at every level of our supply chain with the same vulnerabilities we continue to see: default credentials, lack of patching, weak passwords, etc,โ€ he added.

Aside from potential disruption, Terrill says that nation-states might target ISPs โ€œeither as a pivot point into another environment or a collection point for a lot of data that traverses their infrastructure. Itโ€™s why when youโ€™re thinking about attacker personas and capabilities, you donโ€™t worry that much about breaking encryption โ€“ unless youโ€™re worried about nation-states.”

“The joke in the hacker community is that โ€˜math is hard,โ€™ insinuating that you go after the endpoint as the data is already decrypted by that point.โ€

Author

Phosphorus Cybersecurity

Phosphorus Cybersecurityยฎ is the leading xTended Security of Thingsโ„ข platform designed to find, fix, and monitor the rapidly growing and often unmonitored Things of the enterprise xIoT landscape.