News

“These Cyber Ghosts Are Haunting Us”: Chinese Hackers Breach US National Guard and Stay Undetected for Months

“These Cyber Ghosts Are Haunting Us”: Chinese Hackers Breach US National Guard and Stay Undetected for Months
Illustration of a cyberattack on the US Army National Guard's network, generated by artificial intelligence.
IN A NUTSHELL
  • 🔍 Salt Typhoon, a Chinese state-sponsored hacking group, infiltrated the US Army National Guard’s network for nine months.
  • 🛡️ The hackers stole sensitive data, including personally identifiable information of service members and network diagrams.
  • 🔧 Salt Typhoon exploited vulnerabilities in Cisco routers, deploying custom malware like JumblePath and GhostSpider.
  • 🌐 The breach highlights the urgent need for enhanced cybersecurity measures to protect critical national infrastructure.

The recent infiltration of the US Army National Guard by a Chinese state-sponsored hacking group known as Salt Typhoon has sent shockwaves through the cybersecurity community. This breach, which lasted an alarming nine months, underscores the vulnerability of critical national infrastructure to persistent cyber threats. As more details emerge, it’s becoming clear that the implications of this breach could be far-reaching, affecting not just military operations but also the personal security of service members and potentially other state networks. This article delves into the intricate details of the breach, the methods employed by the hackers, and the broader implications for national security.

The Breach: Nine Months of Undetected Intrusion

The Department of Homeland Security has confirmed that Salt Typhoon, a notorious Chinese hacking group, was present within the US Army National Guard’s network from March to December 2024. During this time, the hackers managed to remain undetected, a testament to their sophisticated techniques and the potential gaps in cybersecurity defenses. The stolen data includes sensitive information such as administrator credentials, network diagrams, and personally identifiable information (PII) of service members.

What makes this breach particularly concerning is the fact that the hackers accessed data traffic not just within the state network but also between other US states and territories. This lateral movement capability suggests that Salt Typhoon could have extended their reach to other critical government and military networks, posing a significant threat to national security. The breach highlights the need for a robust cybersecurity framework to protect against such persistent threats.

“Your Mac Is at Risk!”: Chrome’s Swift Exit from macOS Big Sur Demands Immediate Update to Avoid Tech Chaos

Hacker Tactics: Exploiting Existing Vulnerabilities

Salt Typhoon is known for its strategy of exploiting existing vulnerabilities, particularly in hardware such as Cisco routers. By targeting known Common Vulnerabilities and Exposures (CVEs), the group can gain initial access to networks before deploying custom malware. This method has been a hallmark of their operations across various sectors, including communications and critical infrastructure.

Reports suggest that the group has previously targeted major telecommunications companies like AT&T and Verizon, using similar tactics. The use of unpatched vulnerabilities and custom malware such as JumblePath and GhostSpider enables them to bypass traditional defenses and maintain a persistent presence within the network. This approach not only facilitates data theft but also allows them to potentially disrupt operations if geopolitical tensions escalate.

“Cyber Warfare Is the Future!”: Trump’s $1 Billion Offensive Cyber Operations Bill Sparks Global Shockwaves in Military Strategy

Salt Typhoon: A Component of a Larger Strategy

Salt Typhoon is part of a broader “typhoon” organization, which includes other hacker groups such as Brass Typhoon and Volt Typhoon. These groups are tasked with infiltrating core US organizations, including government, military, and critical infrastructure sectors. The overarching goal is to establish a presence within these networks to disrupt operations and access key intelligence in the event of increased geopolitical tensions, particularly regarding Taiwan.

The activities of Salt Typhoon and its affiliated groups reflect a strategic approach to cyber warfare, where the objective is not just immediate disruption but also long-term intelligence gathering and operational readiness. This underscores the need for continuous monitoring and updating of cybersecurity measures to protect against evolving threats.

“Cyber Warfare Is the Future!”: Trump’s $1 Billion Offensive Cyber Operations Bill Sparks Global Shockwaves in Military Strategy

Implications for National Security and Future Measures

The breach of the US Army National Guard by Salt Typhoon has significant implications for national security. It highlights the vulnerabilities in existing cybersecurity frameworks and the need for enhanced measures to protect critical infrastructure. The incident serves as a wake-up call for government agencies to prioritize cybersecurity and invest in technologies that can detect and mitigate such sophisticated threats.

Moving forward, it is crucial for cybersecurity strategies to focus on not only patching known vulnerabilities but also anticipating and countering new methods of attack. Collaboration between government agencies and the private sector is essential to develop a comprehensive defense strategy. As the threat landscape continues to evolve, the question remains: How can we strengthen our defenses to prevent similar breaches in the future, and what role will emerging technologies play in this endeavor?

This article is based on verified sources and supported by editorial technologies.
Rosemary Potter

About the byline

Rosemary Potter

Rosemary Potter covers “technology” and “apps” for Fastweb Media. This beat fits the publication's focus on technology, devices, apps and online safety, with a particular editorial interest in “devices”. Their articles favour a practical approach centred on consequences for readers and everyday uses.