Enable breadcrumbs token at /includes/pageheader.html.twig

CIA Deputy Director: Two Years Later, Salt Typhoon Still Presents ‘Real Threat’

The government needs to do more, intelligence leader says.

 

Salt Typhoon, the state-based adversarial cyber actor of the People’s Republic of China (PRC), continues to pose a great danger to the United States’ critical infrastructure, according to Deputy Director of the Central Intelligence Agency Michael Ellis.

The second-highest official at the CIA warned of the continued issue when speaking at the Billington CyberSecurity Summit on September 8.

The Salt Typhoon cyber marauders, linked to the PRC’s Ministry of State Security, have been active at least since 2019. Now called an advanced persistent threat (APT) actor, Salt Typhoon targeted U.S. telecommunications, internet providers and communications infrastructure, accessing network edge, router, administrative and telecom management systems.

Their high-level tradecraft has exploited exposed devices, credentialing, accounts, configuration access, network traffic and tunneling—creating secure pathways on compromised networks. This has allowed the APT to exfiltrate key data and persist on telecommunications and network infrastructure.

“It has been almost two years since the Salt Typhoon series of exploits has been publicly disclosed,” Ellis stated. “The risk is still high.”

Richard Forno, professor for the Department of Computer Science and Electrical Engineering and associate director of the University of Maryland Baltimore County’s Cybersecurity Institute, categorized the scope and scale of the attack as “breathtaking,” enabling PRC officials to obtain “a large amount of records showing where, when and who specific individuals were communicating with,” Forno stated in a report in The Conversation, published by UMBC.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

In some cases, Salt Typhoon obtained access to the contents of phone calls and text messages, Forno noted.

For the CIA deputy director, this type of cyber espionage is especially troubling given that “it is still a very real threat.”

Ellis also emphasized that the risk to U.S. critical infrastructure, beyond telecommunications, continues.

“This is primarily, but not exclusively, a China issue, but these threats to our critical infrastructure—whether it is telecom, whether it is the electric sector,  or water—which we saw that recently with Iranian threat actors—there is a whole host of threats to our critical infrastructure,” he said.

In addition, Ellis said that the government “needs to also do a better job” in helping  the private sector to protect itself against these APTs—given that these threats are coming from nation-state adversaries.

“If Chinese or Iranian missiles were hitting U.S. critical infrastructure, no one would say, ‘Well, the operator of that critical infrastructure, the operator of the power plant really should build their own air defense system,’” Ellis stressed. “No, they would say the government has responsibility to help protect this infrastructure. Even though it is being operated by the private sector, it is the same in the cyber domain.

 

 

 

 

 

 

 

Image
CIA Deputy Director Michael Ellis
If Chinese or Iranian missiles were hitting U.S. critical infrastructure, no one would say, ‘Well, the operator of that critical infrastructure, the operator of the power plant really should build their own air defense system.’ No, they would say the government has responsibility to help protect this infrastructure.
Michael Ellis
Deputy Director of the CIA

 

The deputy director also confirmed that the CIA was partnering with the Department of Homeland Security, the Cybersecurity and Infrastructure Security Agency (CISA) and industry counterparts about the threats.

“CIA is taking part in that as well,” he stated.

Moreover, with more sophisticated surveillance technology from adversaries, the CIA is pivoting toward the goal of “more aggressive operations and more technical proficiency” over the next several years, Ellis shared. As part of that shift, the CIA has added the largest team to its operations directorate in 20 years.

“When I think about that challenge of China and the economic competition, I think success will be if we have delivered to the president and other policymakers a decisive intelligence advantage in that competition,” Ellis stated. “If we make sure that they always have an intelligence picture, just like an absolute resolve, where you help enable a military operation by delivering a flawless intelligence picture, we need to continue to deliver a flawless intelligence picture to U.S. policymakers.”

In addition to the PRC, the CIA deputy director identified “enduring challenges” from Russia and Iran, as well as terrorism threats.

“When I think about where we need the CIA to be five years from now, it is an agency that is the world’s leading intelligence service, embracing these advanced technology tools, including artificial intelligence tools, to . . . telling the truth to policymakers on the most important issues of the day,” Ellis stated.

 

Comments

The content of this field is kept private and will not be shown publicly.

Plain text

  • No HTML tags allowed.
  • Lines and paragraphs break automatically.
  • Web page addresses and email addresses turn into links automatically.