Target Industry

Telecommunications, government, transportation, lodging, defence, and critical infrastructure worldwide. Opportunistic use of compromised network devices for pivoting across industries.

Overview

A joint advisory from multiple international cyber agencies highlights a sustained campaign by Chinese state-sponsored Advanced Persistent Threat (APT) actors targeting backbone and edge routers, as well as provider and customer infrastructure globally. The activity overlaps with industry-tracked clusters such as Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor. 

The campaign, ongoing since at least 2021, leverages compromised network devices and trusted provider interconnections to maintain long-term persistence and enable espionage at scale. While zero-days have not yet been observed, actors have had notable success exploiting known vulnerabilities such as: 

  • CVE-2024-21887 (Ivanti Connect Secure command injection) 
  • CVE-2024-3400 (Palo Alto Networks GlobalProtect RCE) 
  • CVE-2023-20273 (Cisco IOS XE privilege escalation) 
  • CVE-2023-20198 (Cisco IOS XE authentication bypass) 
  • CVE-2018-0171 (Cisco IOS/IOS XE Smart Install RCE) 

These intrusions allow actors to exfiltrate sensitive data, monitor communications, and track global targets. 

Impact

If successful, attackers can: 

  • Establish persistent, long-term access to critical networks. 
  • Collect sensitive credentials and communications via traffic mirroring or packet capture. 
  • Exfiltrate data through covert tunnels and peering connections. 
  • Disrupt or modify network configurations for further espionage operations. 

The scale of targeting poses significant risks to national security, telecommunications integrity, and the confidentiality of government and enterprise communications. 

Vulnerability Detection

Organisations should prioritise patching affected devices, particularly Cisco, Palo Alto, and Ivanti appliances vulnerable to the CVEs listed above. Audit SNMP, SSH, and TACACS+/RADIUS configurations for unauthorised changes. Check for suspicious tunnels, packet capture processes, and unexpected local accounts on routers. 

Exploitation

The APT cluster primarily exploits known, publicly available vulnerabilities and weak configurations. Exploitation tradecraft includes double-encoded requests, custom SFTP clients, malicious use of Cisco Guest Shell, and manipulation of ACLs and routing tables. PoC exploit code exists for several targeted CVEs, and observed exploitation activity is ongoing. 

Containment, Mitigations & Remediations

  • Apply vendor patches immediately for affected devices. 
  • Restrict management access to out-of-band networks or dedicated management VRFs. 
  • Enforce strong authentication (e.g., MFA, PKI) and disable password-only access. 
  • Disable unused services and protocols (e.g., Telnet, SNMPv1/2, Smart Install). 
  • Monitor for suspicious tunnels (GRE, IPsec), PCAP collection, and Guest Shell activity. 
  • Verify firmware integrity with vendor-provided tools. 

Threat Landscape

Telecommunications and ISP infrastructure remain high-value targets due to their centrality in global communications. The campaign demonstrates China’s long-term objective of building a global espionage system by compromising provider networks and exploiting trust relationships. The use of routers as covert collection points highlights the importance of supply-chain and infrastructure-layer security. 

Threat Group

The activity is attributed to PRC state-sponsored APT actors, overlapping with industry designations such as Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor. These groups are associated with Chinese intelligence and military units, supported by front companies such as Sichuan Juxinhe Network Technology and Beijing Huanyu Tianqiong Information Technology. 

Further Information

https://media.defense.gov/2025/Aug/22/2003786665/-1/-1/0/CSA_COUNTERING_CHINA_STATE_ACTORS_COMPROMISE_OF_NETWORKS.PDF

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content