Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
Essential information
- Published
- 28/08/2025 15:03
- Modified
- 28/08/2025 15:31
- Tags
- 2025-08-28 apt edge devices salt typhoon
- Related entities
- 6 vulnerabilities (cve), 92 observables, 1 intrusion sets (apt), 31 techniques (mitre), 8 others
Description
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (6)
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected …
- Attack vector
- NETWORK
- Published
- 03/11/2021
- Modified
- 14/01/2026
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the …
- Attack vector
- Network
- Published
- 23/10/2023
- Modified
- 21/12/2025
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker …
- Attack vector
- Network
- Published
- 16/10/2023
- Modified
- 21/12/2025
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
Observables (92)
91.245.253.9991.231.186.22789.41.26.14289.117.2.3974.48.84.11985.195.89.9474.48.78.6674.48.78.11663.245.1.3463.245.1.1363.141.234.10961.19.148.6645.61.165.15745.61.159.2545.61.154.13045.61.151.1245.61.149.6245.61.149.20045.61.134.22345.61.133.6145.61.133.3145.61.133.15745.61.132.12545.59.118.13645.146.120.21345.146.120.21045.125.67.22645.125.64.19538.71.99.14537.120.239.52212.236.17.237193.43.104.185193.239.86.146193.239.86.132172.86.80.15172.86.70.73172.86.65.145172.86.124.235172.86.108.11172.86.106.15172.86.102.83172.86.101.123167.88.175.231167.88.175.175167.88.173.58167.88.173.252167.88.172.70167.88.164.166164.82.20.53146.70.79.81146.70.79.68144.172.79.4144.172.76.213142.171.227.1614.143.247.202107.189.15.206104.194.154.222104.194.154.150104.194.153.181104.194.147.15104.194.129.137103.7.58.162103.253.40.199103.168.91.2311.222.84.2989.117.1.14745.61.134.13445.61.133.7945.61.133.7745.61.128.2945.59.120.17143.254.132.11823.227.202.25323.227.199.7723.227.196.22193.56.255.210172.86.106.39172.86.106.234167.88.173.158146.70.24.144104.194.150.26103.199.17.23859.148.233.250190.131.194.9045.125.67.1445.181.132.955a62b764850d52e01eddf735a5768aae584087804802edc8a5a14e7f60b2266439cc517c39f7402ff2bbba1ea0f34b262f158ff31e00d39d89bbc471d04e8fca60a034cabe18e4f4da692ea0b7f24e31696f8b4fe8a130dbbe3c7c15cea6bde24cccc1fb0a73ae9ea1abc3d11c16ae83b9a7cf62ebe6d144dfc5e19b579a99bad062a9d31cf30bfe8b448f47e36909f3a921b4ff803cf3a61985d8a10f0fe594b405b92ed0fc21f1
Intrusion sets (APT) (1)
-
The MITRE Corporation Confidence 100
[Salt Typhoon](https://attack.mitre.org/groups/G1045) is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14
Techniques (MITRE) (31)
-
Exfiltration Over Alternative Protocol
-
Obtain Capabilities
-
Acquire Infrastructure
-
Create Account
-
Protocol Tunneling
-
Non-Standard Port
-
Non-Application Layer Protocol
-
Trusted Relationship
-
Data from Local System
-
Gather Victim Network Information
-
Remote Services
-
System Network Configuration Discovery
-
Indicator Removal
-
Hide Artifacts
-
System Information Discovery
-
Process Discovery
-
Application Layer Protocol
-
Active Scanning
-
Create or Modify System Process
-
System Services
-
Account Manipulation
-
Deobfuscate/Decode Files or Information
-
System Network Connections Discovery
-
Obfuscated Files or Information
-
Subvert Trust Controls
-
Compromise Infrastructure
-
Impair Defenses
-
Exploit Public-Facing Application
-
Proxy
-
OS Credential Dumping
-
Command and Scripting Interpreter
Others (8)
- New Zealand
- Australia
- Canada
- United Kingdom of Great Britain and Northern Ireland
- United States of America
- Government
- 2a10:1fc0:7::f19c
- 2001:41d0:700:65dc::f656