Target Industry
Telecommunications, government, transportation, lodging, defence, and critical infrastructure worldwide. Opportunistic use of compromised network devices for pivoting across industries.
Overview
A joint advisory from multiple international cyber agencies highlights a sustained campaign by Chinese state-sponsored Advanced Persistent Threat (APT) actors targeting backbone and edge routers, as well as provider and customer infrastructure globally. The activity overlaps with industry-tracked clusters such as Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor.
The campaign, ongoing since at least 2021, leverages compromised network devices and trusted provider interconnections to maintain long-term persistence and enable espionage at scale. While zero-days have not yet been observed, actors have had notable success exploiting known vulnerabilities such as:
- CVE-2024-21887 (Ivanti Connect Secure command injection)
- CVE-2024-3400 (Palo Alto Networks GlobalProtect RCE)
- CVE-2023-20273 (Cisco IOS XE privilege escalation)
- CVE-2023-20198 (Cisco IOS XE authentication bypass)
- CVE-2018-0171 (Cisco IOS/IOS XE Smart Install RCE)
These intrusions allow actors to exfiltrate sensitive data, monitor communications, and track global targets.
Impact
If successful, attackers can:
- Establish persistent, long-term access to critical networks.
- Collect sensitive credentials and communications via traffic mirroring or packet capture.
- Exfiltrate data through covert tunnels and peering connections.
- Disrupt or modify network configurations for further espionage operations.
The scale of targeting poses significant risks to national security, telecommunications integrity, and the confidentiality of government and enterprise communications.
Vulnerability Detection
Organisations should prioritise patching affected devices, particularly Cisco, Palo Alto, and Ivanti appliances vulnerable to the CVEs listed above. Audit SNMP, SSH, and TACACS+/RADIUS configurations for unauthorised changes. Check for suspicious tunnels, packet capture processes, and unexpected local accounts on routers.
Exploitation
The APT cluster primarily exploits known, publicly available vulnerabilities and weak configurations. Exploitation tradecraft includes double-encoded requests, custom SFTP clients, malicious use of Cisco Guest Shell, and manipulation of ACLs and routing tables. PoC exploit code exists for several targeted CVEs, and observed exploitation activity is ongoing.
Containment, Mitigations & Remediations
- Apply vendor patches immediately for affected devices.
- Restrict management access to out-of-band networks or dedicated management VRFs.
- Enforce strong authentication (e.g., MFA, PKI) and disable password-only access.
- Disable unused services and protocols (e.g., Telnet, SNMPv1/2, Smart Install).
- Monitor for suspicious tunnels (GRE, IPsec), PCAP collection, and Guest Shell activity.
- Verify firmware integrity with vendor-provided tools.
Threat Landscape
Telecommunications and ISP infrastructure remain high-value targets due to their centrality in global communications. The campaign demonstrates China’s long-term objective of building a global espionage system by compromising provider networks and exploiting trust relationships. The use of routers as covert collection points highlights the importance of supply-chain and infrastructure-layer security.
Threat Group
The activity is attributed to PRC state-sponsored APT actors, overlapping with industry designations such as Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor. These groups are associated with Chinese intelligence and military units, supported by front companies such as Sichuan Juxinhe Network Technology and Beijing Huanyu Tianqiong Information Technology.
Further Information
Intelligence Terminology Yardstick













