Skip to main content
Threat IntelligenceEmerging Threats

APT Groups Target Private 5G Networks with Exploits and Evasion

Dimly lit server room with rows of networking equipment and servers.

Approximately three years ago, telecom security teams and government investigators identified unauthorized access to telecom and critical infrastructure networks and, upon further inspection, identified two advanced persistent threat (APT) groups called Salt Typhoon and Volt Typhoon that had infiltrated these networks and were loitering there – accessing sensitive data and potentially positioning themselves for some larger act of espionage in the future.

How Salt Typhoon and Volt Typhoon operated inside hardened networks

The intrusions that first alarmed investigators were not dramatic zero-day strikes. As Joseph Bull, Director at Booz Allen Hamilton, and Mitch Rappard, Director of Wireless Solutions at Palo Alto Networks, described in an interview, the two APT groups mostly exploited known vulnerabilities and poor cyber hygiene rather than novel protocol flaws. Volt Typhoon in particular is "known for, 'living off the land,'" using legitimate credentials and built‑in administrative tools to blend into normal activity. While inside networks, the groups traded SSH keys, created new ones, added Linux accounts, and even established GRE tunnels for command‑and‑control traffic.

Why government and military organizations are building private 5G

Private 5G is being adopted because it gives organizations control over connectivity, data, security, and performance—requirements that matter when missions demand reliable coverage, low latency, resilience, or independence from commercial infrastructure. Joseph Bull put it simply: "Private 5G makes sense when commercial services cannot meet an organization’s operational and security requirements." Use cases named in the interview include smart warehouses and ports, autonomous vehicles, drones, robotics, augmented‑reality maintenance, telemedicine, and critical‑infrastructure management. Adoption, Bull added, is moving from pilots toward selective operational deployments at military installations, test ranges, and logistics facilities.

The attack surface: common vulnerabilities and exploitation paths

Bull and Rappard stressed that private does not mean inherently secure. Private 5G environments combine radios, infrastructure, software‑based network functions, APIs, edge computing, management systems, and multi‑vendor equipment—all potential entry points for adversaries. The familiar weaknesses attackers exploited in the Typhoon intrusions remain central: unpatched routers, exposed management interfaces, weak authentication, stolen credentials, legacy equipment, poor segmentation, and inadequate monitoring. As Bull noted, adversaries do not necessarily attack the radio technology directly; they follow the path of least resistance into connected systems and supplier relationships.

Security architecture: Zero Trust, telemetry, and AI for defense

Both experts emphasized that technology alone is insufficient; private 5G must be "treated as a mission system and secure it by design." That includes applying a Zero Trust model—continuously authenticating users and devices, limiting privileges, and separating management, access controls, users, and operational traffic. Recommended capabilities are specific and comprehensive: phishing‑resistant multifactor authentication, device certificates, secure SIM/eSIM controls, identity and privileged access management, 5G‑aware firewalls, network detection, micro‑segmentation, and Zero Trust network access.

Detection and response require centralized telemetry, behavioral analytics, XDR, SIEM, and automated response. Because software vulnerabilities are a top vector, agencies should deploy cloud, container, Kubernetes, workload, and API security plus continuous asset, vulnerability, configuration, and exposure management. Additional measures named include encryption, key management, DDoS protection, and—where appropriate—radio‑frequency monitoring. Both Bull and Rappard urged using AI defensively as adversaries also leverage AI: "There’s no reason why defenders shouldn’t be putting AI to work for them," Bull said, for tasks such as autonomous detection engineering and real‑time compliance monitoring.

What this means for technologists, procurement leaders, and mission owners

  • Technologists and security teams: Prioritize visibility, segmentation, and continuous patching. Rappard emphasized that many necessary tools for Zero Trust "are difficult to deploy when the network is already built," underscoring the need for a security‑led approach from design through deployment.
  • Procurement and acquisition leaders: Treat supplier obligations as part of mission security. Bull urged requiring suppliers to support patching and logging, and to prepare contractual and technical arrangements for isolation and restoration of compromised functions.
  • Military and mission owners: Match the decision to deploy private 5G to mission needs. Bull advised starting with the mission—use private 5G where commercial services cannot meet operational and security requirements—and plan for red teaming and threat hunting as routine activities.

The record the experts laid out is clear: private 5G can deliver mission‑critical capabilities, but it also relocates familiar vulnerabilities into new topology. If adversaries that experts believe are backed by China can use known gaps and poor hygiene to remain undetected for years, then the defensive imperative is straightforward and demanding—design with Zero Trust, bind suppliers to security responsibilities, deploy telemetry and AI for detection, and assume the adversary will try the simplest path first.

Original story