China-Backed Hackers Target Telecoms and Universities in New Wave of Attacks

Article Highlights
Off On

In a concerning development for global cybersecurity, recent reports have revealed that the China-backed hacker group Salt Typhoon, also known as RedMike, carried out a series of cyberattacks targeting telecommunications companies and universities. Between December 2024 and January 2025, this sophisticated group managed to compromise five additional telecom providers worldwide, including two based in the United States. The attacks exploited unpatched vulnerabilities in Cisco edge devices, specifically leveraging CVE-2023-20198 and CVE-2023-20273, which allowed the hackers to escalate privileges and gain root access. As a result, over 1,000 devices across the globe, including several in the U.S., were infiltrated, highlighting the pervasive threat posed by state-sponsored cyber espionage.

Exploiting Vulnerabilities in Telecom Providers

Salt Typhoon’s campaign meticulously targeted network devices that had not received essential security patches. The vulnerabilities in the Cisco devices, known as zero-day flaws, were disclosed in October 2023, but many organizations had not yet patched their systems. The hackers took advantage of this lapse to infiltrate these critical devices, gaining a foothold in the target networks. The Insikt Group from Recorded Future, which closely monitors such threat activities, identified more than 12,000 Cisco devices worldwide with exposed web interfaces. This shift underscores the evolving tactics of Chinese threat groups that now focus on compromising public-facing network devices to establish long-term espionage capabilities.

Despite robust cybersecurity measures, the affected telecom providers did not detect the breaches until significant damage had been done. The Insikt Group confirmed that half of the compromised devices were located in the United States, South America, and India. The remaining devices were spread across various countries, marking a coordinated and extensive campaign. The senior director of strategic intelligence at Recorded Future, Jon Condra, highlighted the inherent challenges large enterprises face in maintaining effective patch management. Testing patches, planning downtime for updates, and ensuring that workflows remain unaffected are formidable tasks, contributing to such vulnerabilities being left unaddressed.

Targeting Academic Institutions

In addition to telecom companies, Salt Typhoon extended their cyberattacks to several American universities, including UCLA and Loyola Marymount University. The focus on academic institutions is presumed to be driven by the universities’ robust research programs in telecommunications and technology. By infiltrating these universities, the hackers aimed to gain access to cutting-edge research and potentially classified or sensitive information that could benefit Chinese state interests. The persistence and audacity of these attacks highlight the broad scope of targets vulnerable to state-sponsored espionage and reinforce the need for enhanced cybersecurity measures across all sectors.

Recorded Future has called on organizations to prioritize patching vulnerabilities and closely monitor configuration changes. Additionally, the cybersecurity firm advised against exposing administration interfaces and nonessential services to the internet. The recent campaign is reminiscent of previous breaches involving major U.S. telecommunications giants such as AT&T and Verizon. These incidents, which resulted in unauthorized access to the private communications of political figures and government officials, have prompted heightened concern within the U.S. government and the broader tech sector.

Implications and Future Considerations

In a troubling development for global cybersecurity, recent reports have unveiled that a China-backed hacker group known as Salt Typhoon, or RedMike, executed a series of cyberattacks on telecommunications companies and universities. Between December 2024 and January 2025, this highly skilled group successfully breached five more telecom providers worldwide, including two in the United States. The hackers exploited unpatched vulnerabilities in Cisco edge devices, specifically CVE-2023-20198 and CVE-2023-20273, to escalate privileges and gain root access. As a result, over 1,000 devices globally, including several in the U.S., were compromised. This underscores the significant threat posed by state-sponsored cyber espionage. The breaches serve as a stark reminder of the critical importance of maintaining robust cybersecurity measures and regularly updating software to patch vulnerabilities. The affected entities are now grappling with the fallout, assessing the extent of the breaches, and implementing measures to prevent future incidents.

Explore more

How Is OpenAI Building the AI-Native Finance Team?

The traditional image of a bustling corporate finance department overflowing with analysts frantically crunching numbers into spreadsheets has been replaced by a quiet, high-velocity digital nervous system that operates with unprecedented surgical precision. This transformation is currently being led by OpenAI, an organization that is treating artificial intelligence as the foundational architecture of its financial operations rather than a secondary

Can AI Bridge the Gender Gap in Financial Services?

Standing at the precipice of a digital revolution, the financial industry faces a jarring paradox where women populate half the desks but almost none of the corner offices. While women make up nearly half of the financial services workforce, they occupy a staggering 8% of CEO positions in major firms. This disparity is no longer just a social issue; it

Mobile Operators Aim to Avoid 5G Mistakes in 6G Rollout

The global telecommunications landscape is currently vibrating with a cautious intensity as industry leaders reflect on the lessons learned from the previous decade of connectivity hurdles and high-speed promises. While the transition to the fifth generation of mobile networks was meant to usher in an era of instantaneous downloads and automated industrial harmony, many users found the experience to be

Hyperautomation Becomes the New Corporate Nervous System

The modern corporate engine is no longer a collection of gears grinding in isolation but has evolved into a self-correcting organism where every digital impulse triggers a calculated, instantaneous response across the entire organizational architecture. This profound shift marks the era of hyperautomation, a paradigm that transcends the simple mechanical repetition of the past to embrace a holistic, orchestrated ecosystem.

Will LLMs Make Robotic Process Automation Obsolete?

The persistent illusion of total office automation frequently shatters when a single non-standardized PDF document brings a million-dollar robotic process to a grinding halt. Thousands of manual man-hours are still poured into fixing bot errors across global supply chains that were originally marketed as being fully automated. This paradox exists because traditional automation hits a wall when faced with the