https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/ BleepingComputer.com logo * * * * [ ] [Login] [Sign up] * * * * [ ] [Login] [Sign up] * News + Featured + Latest + American Water shuts down online services after cyberattack American Water shuts down online services after cyberattack + Russia arrests US-sanctioned Cryptex founder, 95 other linked suspects Russia arrests US-sanctioned Cryptex founder, 95 other linked suspects + Comcast and Truist Bank customers caught up in FBCS data breach Comcast and Truist Bank customers caught up in FBCS data breach + AT&T, Verizon reportedly hacked to target US govt wiretapping platform AT&T, Verizon reportedly hacked to target US govt wiretapping platform + MoneyGram confirms hackers stole customer data in cyberattack MoneyGram confirms hackers stole customer data in cyberattack + ADT discloses second breach in 2 months, hacked via stolen credentials ADT discloses second breach in 2 months, hacked via stolen credentials + LEGO's website hacked to push cryptocurrency scam LEGO's website hacked to push cryptocurrency scam + Ukrainian pleads guilty to operating Raccoon Stealer malware Ukrainian pleads guilty to operating Raccoon Stealer malware * Tutorials + Latest + Popular + How to access the Dark Web using the Tor Browser How to access the Dark Web using the Tor Browser + How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 + How to use the Windows Registry Editor How to use the Windows Registry Editor + How to backup and restore the Windows Registry How to backup and restore the Windows Registry + How to start Windows in Safe Mode How to start Windows in Safe Mode + How to remove a Trojan, Virus, Worm, or other Malware How to remove a Trojan, Virus, Worm, or other Malware + How to show hidden files in Windows 7 How to show hidden files in Windows 7 + How to see hidden files in Windows How to see hidden files in Windows * Virus Removal Guides + Latest + Most Viewed + Ransomware + Remove the Theonlinesearch.com Search Redirect Remove the Theonlinesearch.com Search Redirect + Remove the Smartwebfinder.com Search Redirect Remove the Smartwebfinder.com Search Redirect + How to remove the PBlock+ adware browser extension How to remove the PBlock+ adware browser extension + Remove the Toksearches.xyz Search Redirect Remove the Toksearches.xyz Search Redirect + Remove Security Tool and SecurityTool (Uninstall Guide) Remove Security Tool and SecurityTool (Uninstall Guide) + How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo + How to remove Antivirus 2009 (Uninstall Instructions) How to remove Antivirus 2009 (Uninstall Instructions) + How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller + Locky Ransomware Information, Help Guide, and FAQ Locky Ransomware Information, Help Guide, and FAQ + CryptoLocker Ransomware Information Guide and FAQ CryptoLocker Ransomware Information Guide and FAQ + CryptorBit and HowDecrypt Information Guide and FAQ CryptorBit and HowDecrypt Information Guide and FAQ + CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ * Downloads + Latest + Most Downloaded + Qualys BrowserCheck Qualys BrowserCheck + STOPDecrypter STOPDecrypter + AuroraDecrypter AuroraDecrypter + FilesLockerDecrypter FilesLockerDecrypter + AdwCleaner AdwCleaner + ComboFix ComboFix + RKill RKill + Junkware Removal Tool Junkware Removal Tool * Deals + Categories + eLearning eLearning + IT Certification Courses IT Certification Courses + Gear & Gadgets Gear + Gadgets + Security Security * VPNs + Popular + Best VPNs Best VPNs + How to change IP address How to change IP address + Access the dark web safely Access the dark web safely + Best VPN for YouTube Best VPN for YouTube * Forums * More + Startup Database + Uninstall Database + Glossary + Chat on Discord + Send us a Tip! + Welcome Guide ThreatLocker Zero Trust World conference * Home * News * Security * AT&T, Verizon reportedly hacked to target US govt wiretapping platform * * AT&T, Verizon reportedly hacked to target US govt wiretapping platform By Ionut Ilascu * October 7, 2024 * 10:51 AM * 4 [Chinese_hackers] Multiple U.S. broadband providers, including Verizon, AT&T, and Lumen Technologies, have been breached by a Chinese hacking group tracked as Salt Typhoon, the Wall Street Journal reports. The purpose of the attack appears to be for intelligence collection as the hackers might have had access to systems used by the U.S. federal government for court-authorized network wiretapping requests. It is unclear when the intrusion occurred, but WSJ cites people familiar with the matter, saying that "for months or longer, the hackers might have held access to network infrastructure used to cooperate with lawful U.S. requests for communications data." Salt Typhoon is the name that Microsoft gave to this particular China-based threat actor. Other cybersecurity companies are tracking the adversary as Earth Estries (Trend Micro), FamousSparrow (ESET), Ghost Emperor (Kaspersky), and UNC2286 (Mandiant, now part of Google Cloud). Capturing sensitive traffic According to the WSJ, the attack was discovered in recent weeks and is being investigated by the U.S. government and security experts in the private sector. The impact of the attack - amount and type of observed and exfiltrated data - is still being assessed, people with information about the intrusion told WSJ. "The hackers appear to have engaged in a vast collection of internet traffic from internet service providers that count businesses large and small, and millions of Americans, as their customers" - Wall Street Journal Apart from breaching service providers in the U.S. Salt Typhoon may have hacked similar entities in other countries, too. Salt Typhoon has been active since at least 2019 and is considered a sophisticated hacking group focusing on government entities and telecommunications companies typically in the Southeast Asia region. Security researchers also found that the threat actor attacked hotels, engineering companies, and law firms in Brazil, Burkina Faso, South Africa, Canada, Israel, France, Guatemala, Lithuania, Saudi Arabia, Taiwan, Thailand, and the United Kingdom. The hackers usually obtain initial access to the target network by exploiting vulnerabilities, such as the ProxyLogon vulnerabilities in Microsoft Exchange Server (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065). In previous attacks attributed to Salt Typhoon/Ghost Emperor, the threat actor used a custom backdoor called SparrowDoor, customized versions of the Mimikatz tool for extracting authentication data, and a Windows kernel-mode rootkit Demodex. Investigators are still looking for the initial access method for the recent attack. The WSJ says that one avenue being explored is gaining access to Cisco routers responsible for routing internet traffic. However, a Cisco spokesperson told WSJ that the company was looking into the matter but had received no indication that Cisco networking equipment was involved in the breach. BleepingComputer contacted AT&T about the alleged breach and was told they "are not commenting on the WSJ report." Lumen also declined to comment. Verizon has not responded to our emails, and we will update the story if we receive a reply. Chinese APT hacking groups have been increasingly targeting U.S. and European networking devices and ISPs in cyberespionage attacks. In August, cybersecurity researchers at Lumen's Black Lotus Labs disclosed that the Chinese threat actors known as "Volt Typhoon" exploited a zero-day flaw in Versa Director to steal credentials and breach corporate networks. During these attacks, the threat actors breached multiple ISPs and MSPs in the U.S. and India, which is not believed to be related to the recent breaches. In September, Black Lotus Labs and law enforcement disrupted a massive Chinese botnet named "Raptor Train" that compromised over 260,000 SOHO routers, IP cameras with malware. This botnet was used by the "Flax Typhoon" threat actors for DDoS attacks and as a proxy to launch stealthy attacks on other organizations. While these attacks have been attributed to different Chinese hacking groups, they are believed to operate under the same umbrella, commonly sharing infrastructure and tools. Related Articles: Verizon outage: iPhones, Android devices stuck in SOS mode US proposes ban on connected vehicle tech from China, Russia Chinese botnet infects 260,000 SOHO routers, IP cameras with malware AT&T pays $13 million FCC settlement over 2023 data breach Microsoft: Stealthy Flax Typhoon hackers use LOLBins to evade detection * AT&T * China * Salt Typhoon * Verizon * Wiretap * * * * * Ionut Ilascu Ionut Ilascu is a technology writer with a focus on all things cybersecurity. The topics he writes about include malware, vulnerabilities, exploits and security defenses, as well as research and innovation in information security. His work has been published by Bitdefender, Netgear, The Security Ledger and Softpedia. * Previous Article * Next Article Comments * Wannabetech1 Photo Wannabetech1 - 7 hours ago + + So the government hackers got hacked; too funny! * GT500 Photo GT500 - 7 hours ago + + The government shouldn't have a system to wiretap ISP's... * DyingCrow Photo DyingCrow - 5 hours ago + + This prompts for the opening of a big, nasty can of worms. * NoneRain Photo NoneRain - 3 hours ago + + State-sponsored Chinese groups just do whatever they want and get away with it. US: "oh no, they hacked our critical infrastructure and stole data....again! Oh well, that's how they are :)" Post a Comment Community Rules You need to login in order to post a comment [Login] Not a member yet? Register Now You may also like: [INS::INS] Popular Stories * Kaspersky Google removes Kaspersky's antivirus software from Play Store * Comcast Comcast and Truist Bank customers caught up in FBCS data breach * Highline Public Schools Highline Public Schools confirms ransomware behind shutdown Sponsor Posts * Data Theft in Salesforce: Manipulating Public Links * Reduce cyber risk by securing passwords in your employee onboarding * Discover how to build custom dictionaries in your AD password policy * Hybrid Analysis Bolstered by Criminal IP's Comprehensive Domain Intelligence * See how you can manage shadow IT and reduce your attack surface Follow us: * * * * * Main Sections * News * VPN Buyer Guides * SysAdmin Software Guides * Downloads * Virus Removal Guides * Tutorials * Startup Database * Uninstall Database * Glossary Community * Forums * Forum Rules * Chat Useful Resources * Welcome Guide * Sitemap Company * About BleepingComputer * Contact Us * Send us a Tip! * Advertising * Write for BleepingComputer * Social & Feeds * Changelog Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2024 Bleeping Computer^(r) LLC - All Rights Reserved Login Username [ ] Password [ ] [*] Remember Me [ ] Sign in anonymously [Login] Sign in with Twitter button Sign in with Twitter --------------------------------------------------------------------- Not a member yet? Register Now Reporter Help us understand the problem. What is going on with this comment? * ( )Spam * ( )Abusive or Harmful * ( )Inappropriate content * ( )Strong language * ( )Other [ ] * [ ] Read our posting guidelinese to learn what content is prohibited. Submitting... SUBMIT