Cisco Talos. (2025, February 20). Weathering the storm: In the midst of a Typhoon. Retrieved February 24, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.004 SSH |
GroupSalt Typhoon | Salt Typhoon has modified the loopback address on compromised switches and used them as the source of SSH connections to additional devices within the target environment, allowing them to bypass access control lists (ACLs). |
| T1040 Network Sniffing |
MalwareJumbledPath | JumbledPath has the ability to perform packet capture on remote devices via actor-defined jump-hosts. |
| T1040 Network Sniffing |
GroupSalt Typhoon | Salt Typhoon has used a variety of tools and techniques to capture packet data between network interfaces. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupSalt Typhoon | Salt Typhoon has exfiltrated configuration files from exploited network devices over FTP and TFTP. |
| T1098.004 SSH Authorized Keys |
GroupSalt Typhoon | Salt Typhoon has added SSH authorized_keys under root or other users at the Linux level on compromised network devices. |
| T1104 Multi-Stage Channels |
MalwareJumbledPath | JumbledPath can communicate over a unique series of connections to send and retrieve data from exploited devices. |
| T1110.002 Password Cracking |
GroupSalt Typhoon | Salt Typhoon has cracked passwords for accounts with weak encryption obtained from the configuration files of compromised network devices. |
| T1136 Create Account |
GroupSalt Typhoon | Salt Typhoon has created Linux-level users on compromised network devices through modification of `/etc/shadow` and `/etc/passwd`. |
| T1190 Exploit Public-Facing Application |
GroupSalt Typhoon | Salt Typhoon has exploited CVE-2018-0171 in the Smart Install feature of Cisco IOS and Cisco IOS XE software for initial access. |
| T1560 Archive Collected Data |
MalwareJumbledPath | JumbledPath can compress and encrypt exfiltrated packet captures from targeted devices. |
| T1572 Protocol Tunneling |
GroupSalt Typhoon | Salt Typhoon has modified device configurations to create and use Generic Routing Encapsulation (GRE) tunnels. |
| T1587.001 Malware |
GroupSalt Typhoon | Salt Typhoon has used custom tooling including JumbledPath. |
| T1588.002 Tool |
GroupSalt Typhoon | Salt Typhoon has used publicly available tooling to exploit vulnerabilities. |
| T1590.004 Network Topology |
GroupSalt Typhoon | Salt Typhoon has used configuration files from exploited network devices to help discover upstream and downstream network segments. |
| T1602.002 Network Device Configuration Dump |
GroupSalt Typhoon | Salt Typhoon has attempted to acquire credentials by dumping network device configurations. |
| T1665 Hide Infrastructure |
MalwareJumbledPath | JumbledPath can use a chain of jump hosts to communicate with compromised devices to obscure actor infrastructure. |
| T1685 Disable or Modify Tools |
MalwareJumbledPath | JumbledPath can impair logging on all devices used along its connection path to compromised hosts. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareJumbledPath | JumbledPath can clear logs on all devices used along its connection path to compromised network infrastructure. |
| T1685.006 Clear Linux or Mac System Logs |
GroupSalt Typhoon | Salt Typhoon has cleared logs including .bash_history, auth.log, lastlog, wtmp, and btmp. |
| T1686 Disable or Modify System Firewall |
GroupSalt Typhoon | Salt Typhoon has made changes to the Access Control List (ACL) and loopback interface address on compromised devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.