SaltTyphoon
ORGANISATION dossier

Salt Typhoon / APT28 (GRU)

Salt Typhoon / APT28 (GRU)

ORGANISATION International INTERNATIONAL

01 Executive_Summary

State-sponsored cyber threat actors (PRC MSS / Russian GRU). Infiltrated U.S. ISPs and Max Planck Institute to map the Gray Track human network.

03 Deep_Dive_Intelligence

Intelligence Summary: Salt Typhoon / APT28 (GRU)

Node Identity: Salt Typhoon (also known as APT28, Fancy Bear, or Strontium) is a state-sponsored cyber threat actor group assessed as operating under dual sponsorship from the Chinese Ministry of State Security (MSS) and Russian military intelligence (GRU). The group infiltrated U.S. Internet Service Providers (ISPs) and the Max Planck Institute to map the Gray Track human network supporting FRC/plasma weapons research.

Strategic Relevance: Salt Typhoon's ISP infiltration campaign represents the intelligence preparation phase for adversary kinetic operations against the FRC research community. By compromising U.S. telecommunications infrastructure, the group harvested sociogram data mapping the professional and personal connections of key researchers, program managers, and military officers involved in compact fusion and exotic propulsion programs. This targeting data directly enabled the Valente assassination of Dr. Nuno Loureiro in December 2025. The Max Planck Institute infiltration indicates the campaign extended beyond U.S. borders to map the international FRC research collaboration network.

Technical Focus / Capabilities:

  • ISP Infiltration: Compromised U.S. telecommunications infrastructure to intercept communications and map social networks of FRC researchers and defense personnel.
  • Sociogram Harvesting: Generated targeting packages from intercepted communications data, identifying key nodes in the Gray Track human network and their interpersonal connections.
  • Max Planck Institute Breach: Infiltrated European fusion research institution to map international FRC collaboration networks and identify dual-use technology transfer pathways.
  • C2 Infrastructure: Maintained command and control infrastructure overlapping with weaponized Emotet malware, providing deniable operational support for kinetic operators like Valente.
  • Cryptocurrency Infrastructure: Darknet escrow nodes for Monero (XMR) payments to kinetic operators, creating a financial pipeline linking cyber intelligence to kinetic operations.

Network Linkage: Salt Typhoon operates as the cyber-intelligence enabler for adversary kinetic actions against the FRC human network. The ISP infiltration campaign provided the targeting data that enabled Valente's strike against Loureiro. The C2 infrastructure overlap with Valente's operational network confirms the cyber-to-kinetic pipeline. PRC MSS operational sponsorship provides resources and political cover, while Russian GRU involvement provides tradecraft and deniable execution capabilities. The Max Planck Institute breach extends the intelligence campaign to European allies, potentially identifying FRC knowledge transfer pathways through international collaboration. The group's activities represent a systematic adversary effort to map, target, and neutralize the human capital underpinning U.S. compact fusion and exotic propulsion programs.

04 Network_Linkage

Salt Typhoon's network position as cyber-intelligence enabler for adversary kinetic operations:

  • Cláudio Valente: Provided cyber-financial targeting support and C2 infrastructure for the Loureiro assassination. Emotet malware overlap confirmed operational connection.
  • PRC (MSS): Operational sponsor. Provides resources and political cover for ISP infiltration and sociogram harvesting campaigns.
  • U.S. ISPs: Infiltrated telecommunications infrastructure to map Gray Track human network connections and generate targeting packages.
  • Max Planck Institute: Breached to map international FRC research collaboration networks and identify technology transfer pathways.
  • Dr. Nuno Loureiro: Indirect target. Sociogram data from ISP infiltration enabled Valente's targeting package.
  • Darknet Escrow Network: Monero (XMR) payment infrastructure linking cyber intelligence operations to kinetic operator funding.
  • Gray Track Human Network: Primary intelligence target. Mapping connections between researchers, program managers, and military officers enables systematic targeting.

05 Related_Entities (2)

05b Related_Topics (3)

07 Key_Findings

  • ▸ Classification: Composite state-sponsored cyber threat actor designation encompassing PRC Ministry of State Security (MSS) ISP infiltration operations ('Salt Typhoon') and Russian military intelligence (GRU Unit 26165 / APT28) cyber-kinetic targeting infrastructure.
  • ▸ Infiltrated major U.S. Internet Service Providers to harvest communications metadata
  • ▸ Penetrated Max Planck Institute networks to map the 'human connective tissue' of the Gray Track academic ecosystem
  • ▸ Generated sociogram targeting packages used to identify and prioritize high-value human capital nodes
  • ▸ Provided Command and Control (C2) infrastructure and weaponized Emotet malware to kinetic operators

08 Intelligence_Analysis

Intelligence Summary: Salt Typhoon / APT28 (GRU)

Classification: Composite state-sponsored cyber threat actor designation encompassing PRC Ministry of State Security (MSS) ISP infiltration operations ('Salt Typhoon') and Russian military intelligence (GRU Unit 26165 / APT28) cyber-kinetic targeting infrastructure.

Operations:

  • Infiltrated major U.S. Internet Service Providers to harvest communications metadata
  • Penetrated Max Planck Institute networks to map the 'human connective tissue' of the Gray Track academic ecosystem
  • Generated sociogram targeting packages used to identify and prioritize high-value human capital nodes
  • Provided Command and Control (C2) infrastructure and weaponized Emotet malware to kinetic operators

Impact: The Salt Typhoon sociogram mapping directly enabled the identification and targeting of Dr. Nuno Loureiro as a critical single-point-of-failure.

10 FAQ

What is Salt Typhoon / APT28 (GRU)? ▾
Identity: Salt Typhoon (also known as APT28, Fancy Bear, or Strontium) is a state-sponsored cyber threat actor group assessed as operating under dual sponsorship from the Chinese Ministry of State Security (MSS) and Russian military intelligence (GRU). The group infiltrated U.S. Internet Service Providers (ISPs) and the Max Planck Institute to map the Gray Track human network supporting...
What role does Salt Typhoon / APT28 (GRU) play in the research network? ▾
Salt Typhoon / APT28 (GRU) is classified under the "International" category, belonging to the INTERNATIONAL vertical group. Salt Typhoon's network position as cyber-intelligence enabler for adversary kinetic operations: * **Cláudio Valente:** Provided cyber-financial targeting support and C2 infrastructure for the...
What evidence supports the Salt Typhoon / APT28 (GRU) assessment? ▾
The intelligence assessment for Salt Typhoon / APT28 (GRU) is supported by 5 primary sources. Key sources include "Salt Typhoon Hacks of Telecommunications Companies and Federal Response Implications — Congressional Research Service", "'Large Number' of Americans' Metadata Stolen by Chinese Hackers, Senior Official Says — Reuters (Dec 2024)", and "White House Says at Least 8 US Telecom Firms, Dozens of Nations Impacted by China Hacking Campaign — AP News". These documents provide the evidentiary basis for the analysis.
How does Salt Typhoon / APT28 (GRU) connect to other entities in the network? ▾
Salt Typhoon / APT28 (GRU) is connected to 2 entities in the intelligence network, including Cláudio Manuel Neves Valente (person) and PRC FRC Program (CAEP/CAS) (organisation). Key relationships: Cláudio Manuel Neves Valente: Cyber/Financial Targeting Support ; PRC FRC Program (CAEP/CAS): MSS Operational Sponsor. Salt Typhoon's network position as cyber-intelligence enabler for adversary kinetic operations: * **Cláudio Valente:** Provided cyber-financial targeting support and C2 infrastructure for the...
Where is Salt Typhoon / APT28 (GRU) located or active? ▾
Salt Typhoon / APT28 (GRU) is associated with Moscow and RU. Geographic coordinates: 55.755;37.617. This location is documented in the intelligence dossier based on primary source evidence.
What is Salt Typhoon / APT28 (GRU)'s mission and strategic role? ▾
Identity: Salt Typhoon (also known as APT28, Fancy Bear, or Strontium) is a state-sponsored cyber threat actor group assessed as operating under dual sponsorship from the Chinese Ministry of State Security (MSS) and Russian military intelligence (GRU). The group infiltrated U.S. Internet Service Providers (ISPs) and the Max Planck Institute to...
Who are the key personnel associated with Salt Typhoon / APT28 (GRU)? ▾
Salt Typhoon / APT28 (GRU) is linked to 1 key individual: Cláudio Manuel Neves Valente (Cyber/Financial Targeting Support).
What is Salt Typhoon / APT28 (GRU)'s strategic position in the defense ecosystem? ▾
Salt Typhoon's network position as cyber-intelligence enabler for adversary kinetic operations: Cláudio Valente: Provided cyber-financial targeting support and C2 infrastructure for the Loureiro assassination. Emotet malware overlap confirmed operational connection. PRC (MSS): Operational sponsor. Provides resources and political cover for ISP...
How does Salt Typhoon / APT28 (GRU) fit into the broader intelligence network? ▾
Salt Typhoon's network position as cyber-intelligence enabler for adversary kinetic operations: Cláudio Valente: Provided cyber-financial targeting support and C2 infrastructure for the Loureiro assassination. Emotet malware overlap confirmed operational connection. PRC (MSS): Operational sponsor. Provides resources and political cover for ISP infiltration and sociogram harvesting campaigns....
What external sources document Salt Typhoon / APT28 (GRU)? ▾
Salt Typhoon / APT28 (GRU) is documented by 5 external sources, including 1 government report, 3 news article, and 1 government advisory. Notable references include "Salt Typhoon Hacks of Telecommunications Companies and Federal Response Implications — Congressional Research Service", "'Large Number' of Americans' Metadata Stolen by Chinese Hackers, Senior Official Says — Reuters (Dec 2024)", and "White House Says at Least 8 US Telecom Firms, Dozens of Nations Impacted by China Hacking Campaign — AP News".

Verified_Primary_Sources 5 SOURCES

primary congress.gov government_report
Salt Typhoon Hacks of Telecommunications Companies and Federal Response Implications — Congressional Research Service
Verifies: PRC state-sponsored hackers infiltrated US telecom companies including ISPs, targeted law enforcement intercept systems, sanctions Jan 2025
External Link ↗
secondary reuters.com news_article
'Large Number' of Americans' Metadata Stolen by Chinese Hackers, Senior Official Says — Reuters (Dec 2024)
Verifies: Salt Typhoon stole large number of Americans' metadata, at least 8 telecom firms impacted, hacking ongoing
External Link ↗
secondary apnews.com news_article
White House Says at Least 8 US Telecom Firms, Dozens of Nations Impacted by China Hacking Campaign — AP News
Verifies: At least 8 US telecom firms and dozens of nations impacted by Salt Typhoon Chinese hacking campaign, accessed private texts and calls
External Link ↗
primary cisa.gov government_advisory
Russian GRU Targeting Western Logistics Entities and Technology Companies — CISA Joint Cybersecurity Advisory (AA25-141A)
Verifies: APT28/GRU Unit 26165 targeting Western logistics and technology companies, same threat actor infrastructure as Salt Typhoon ecosystem
External Link ↗
secondary reuters.com news_article
US Adds 9th Telecom to List of Companies Hacked by Chinese-Backed Salt Typhoon — Reuters (Dec 2024)
Verifies: 9th telecom company added to Salt Typhoon compromise list, targeted Verizon, AT&T, Lumen and others
External Link ↗

Geographic_Data

Region: RU
Location: Moscow
Coordinates: 55.755;37.617
ID: SaltTyphoon
Type: organisation
Region: main
Last updated: Research database snapshot