Researchers claim Salt Typhoon masterminds learned their trade at Cisco Network Academy
The Salt Typhoon hacker group has targeted telecoms operators and US National Guard networks in recent years
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Two key players in the notorious Salt Typhoon hacker group are former Cisco Network Academy trainees, according to researchers at SentinelLabs.
An investigation by the firm suggests Yu Yang and Qiu Daibing used their insider product knowledge to compromise telecoms systems in one of the largest intelligence-gathering operations of the decade.
Salt Typhoon collected unencrypted calls and texts between US presidential candidates, key staffers, and China experts.
The Cisco Network Academy began in 1997 and entered the Chinese market in 1998. It has now trained more than 200,000 students in China - most, of course, perfectly reputable.
Qiu and Yu were apparently top students at the 2012 Cisco Network Academy Cup, representing Southwest Petroleum University. However, a little sleuthing revealed that the pair are co-owners of Beijing Huanyu Tianqiong, with Yu also tied to Sichuan Zhixin Ruijie.
Both of these companies were named in a Salt Typhoon cybersecurity advisory by US authorities.
"Among the content covered in Cisco networking academy were many of the products Salt Typhoon exploited, including Cisco IOS and ASA firewalls," said Dakota Cary, a China-focused consultant at SentinelOne.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Of course, a product training academy educating students on the company’s wares is hardly surprising. More notable is the fact that two students from a regional university, with limited recognition in IT and cybersecurity education participated in the Cisco Network Academy and went on to run one of the most expansive collection operations against global telecommunications firms ever detected and disclosed publicly."
Salt Typhoon has been on a rampage
Salt Typhoon has quickly emerged as one of the most notorious state-sponsored hacker groups globally. As ITPro reported last year, a campaign by the threat group saw it intercept unencrypted calls and texts from high-value US political targets dating back to 2019.
Targets in this campaign spanned a wide range of sectors, focusing mainly on large backbone routers of major telecommunications providers, as well as provider edge and customer edge routers.
The group is still active, with the US Department of Defense (DoD) revealing in July that Salt Typhoon had breached and laid low in the network of an unnamed US state National Guard for almost a year.
In September, the FBI warned that the group was ramping up attacks globally, having hit more than 60 organizations in 80 countries.
Education schemes could cause blowback
SentinelLabs said the unmasking of Qiu and Yu reveals the long-term security risks of global tech education pipelines, which can be exploited by state-linked operators.
"The episode suggests that offensive capabilities against foreign IT products likely emerge when companies begin supplying local training and that there is a potential risk of such education initiatives inadvertently boosting foreign offensive research," said Cary.
"Qiu and Yu are not an oddity; they are evidence of a world in which today’s students can become tomorrow’s rivals with little more than time, opportunity, and a different notion of whose security they serve."
A spokesperson for Cisco told ITPro the networking giant "remains committed to helping people around the world gain the foundational digital skills needed to access careers in technology".
“Cisco Networking Academy (NetAcad) is a skills-to-jobs program that teaches foundational technology skills and digital literacy, helping millions of students obtain basic certifications for entry-level IT jobs each year. This program is open to everyone," the spokesperson commented.
"Since its inception in 1997, the program has educated over 28 million students across 195 countries, in partnership with more than 12,000 institutions and organizations.
"In 2012, NetAcad hosted one global competition series called NetRiders and published a list of APAC regional winners."
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
- A new 'top-tier' Chinese espionage group is stealing sensitive data
- Chinese hackers are using ‘stealthy and resilient’ Brickstorm malware to hide in networks for months at a time
- China cyber threats: What businesses can do to protect themselves
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Low-budget devices are the biggest casualty of the RAM crisisNews Say goodbye to budget devices; vendors are doubling down on high-end options to absorb costs
-
Sectigo taps Clint Maddox to lead global field operationsReviews The appointment follows a year of strong momentum for the security vendor as it expands its global channel footprint
-
CISOs are keen on agentic AI, but they’re not going all-in yetNews Many security leaders face acute talent shortages and are looking to upskill workers
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
Using AI to generate passwords is a terrible idea, experts warnNews Researchers have warned the use of AI-generated passwords puts users and businesses at risk
-
Researchers called on LastPass, Dashlane, and Bitwarden to up defenses after severe flaws put 60 million users at risk – here’s how each company respondedNews Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking
-
‘They are able to move fast now’: AI is expanding attack surfaces – and hackers are looking to reap the same rewards as enterprises with the technologyNews Potent new malware strains, faster attack times, and the rise of shadow AI are causing havoc
-
Ransomware gangs are using employee monitoring software as a springboard for cyber attacksNews Two attempted attacks aimed to exploit Net Monitor for Employees Professional and SimpleHelp
-
Security expert warns Salt Typhoon is becoming 'more dangerous' after Norwegian authorities lift lid on critical infrastructure hacking campaignNews The Chinese state-backed hacking group has waged successful espionage campaigns against an array of organizations across Norway.
-
Notepad++ hackers remained undetected and pushed malicious updates for six months – here’s who’s responsible, how they did it, and how to check if you’ve been affectedNews Hackers remained undetected for months and distributed malicious updates to Notepad++ users after breaching the text editor software – here's how to check if you've been affected.
