Inside the Telecom Attack Surface: SS7, BGP Hijacking, and the Technical Reality of Nation-State Intrusions
Nation-state actors abuse SS7, BGP, and unpatched telecom routers, including Salt Typhoon persistence via GRE tunnels.
Cyble describes how nation-state operators abuse telecom trust assumptions in SS7, Diameter, and BGP rather than relying only on zero-days. DHS has said U.S. carriers are exposed to SS7 and Diameter attacks, and a 2010 China Telecom BGP incident briefly drew about 15 percent of internet destinations through Chinese servers. A 2025 CISA advisory says PRC actors, including the Salt Typhoon cluster, hit backbone and edge routers using CVE-2024-21887, CVE-2023-46805, CVE-2024-3400, CVE-2023-20273, and CVE-2023-20198, then maintained access with GRE tunnels.
60