Two individuals associated with the Chinese state-sponsored hacking group Salt Typhoon were identified as former participants in the Cisco Networking Academy, raising concerns about the unintended consequences of global IT training programs. These individuals, Yuyang and Qiu Daibing, later became co-owners of companies implicated in Salt Typhoon's operations, which targeted Cisco devices and exploited vulnerabilities to conduct extensive cyberespionage campaigns against Western targets, including U.S. presidential candidates and telecommunications infrastructure.
Salt Typhoon's campaign, first publicly reported in September 2024, compromised over 80 telecommunications companies worldwide, enabling the interception of unencrypted calls, texts, and even breaching lawful intercept (CALEA) systems. The operation highlights the risk that foreign training initiatives may inadvertently enhance the offensive cyber capabilities of adversarial states, especially as China moves to reduce reliance on American-made IT products. U.S. government advisories have warned about Salt Typhoon's sophisticated exploitation of Cisco vulnerabilities to obtain credentials and move laterally within targeted networks.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Reporting and research published in December 2025 tied Yu Yang and Qiu Daibing to Salt Typhoon, connecting their later roles in companies linked to the group with their earlier Cisco Academy participation. The findings highlighted how technical product training may have supported later offensive tradecraft.
A US government cybersecurity advisory identified companies, including Beijing Huanyu Tianqiong, as fronts or entities connected to Salt Typhoon's cyber operations. Yu Yang and Qiu Daibing were described as partial or co-owners of companies named in that advisory.
During the telecom intrusions, Salt Typhoon accessed CALEA lawful intercept systems and intercepted unencrypted communications, including those involving US presidential candidates and Washington, DC China experts.
Salt Typhoon conducted a large-scale espionage campaign that breached at least 80 telecommunications companies globally. The intrusions enabled intelligence collection against sensitive telecom infrastructure and Cisco devices.
The Chinese state-linked espionage group Salt Typhoon was first publicly reported in September 2024, marking the start of public awareness of the campaign.
Records cited by researchers indicate Yu Yang and Qiu Daibing participated as top-performing students in the 2012 Cisco Networking Academy Cup in China, receiving hands-on training with Cisco technologies later central to their alleged operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcecybersecuritynews.com
Open sourcewired.com
Open sourcesentinelone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.