salttyphoon
NODE_ID: SaltTyphoon // STATUS: ACTIVE
Salt Typhoon / APT28 (GRU)
ORGANISATION INTERNATIONAL
01 Executive_Summary
State-sponsored cyber threat actors (PRC MSS / Russian GRU). Infiltrated U.S. ISPs and Max Planck Institute to map the Gray Track human network.
02 Deep_Dive_Intelligence
Intelligence Summary: Salt Typhoon / APT28 (GRU)
Classification: Composite state-sponsored cyber threat actor designation encompassing PRC Ministry of State Security (MSS) ISP infiltration operations ('Salt Typhoon') and Russian military intelligence (GRU Unit 26165 / APT28) cyber-kinetic targeting infrastructure.
Operations:
- Infiltrated major U.S. Internet Service Providers to harvest communications metadata
- Penetrated Max Planck Institute networks to map the 'human connective tissue' of the Gray Track academic ecosystem
- Generated sociogram targeting packages used to identify and prioritize high-value human capital nodes
- Provided Command and Control (C2) infrastructure and weaponized Emotet malware to kinetic operators
Impact: The Salt Typhoon sociogram mapping directly enabled the identification and targeting of Dr. Nuno Loureiro as a critical single-point-of-failure.
03 Network_Linkage
- Cláudio Valente — Cyber-financial targeting support for kinetic strike
- Dr. Nuno Loureiro — Primary target identified via sociogram mapping
- Max Planck Institute — Infiltrated to map Gray Track academic network
- PRC / MSS — Salt Typhoon operational sponsor
- GRU Unit 26165 — APT28 C2 infrastructure provider
System_Actions
SECURE_HASH: 711E04C3
LAST_UPDATED: 2026-06-02
CLASSIFICATION: SECRET//NOFORN
LAST_UPDATED: 2026-06-02
CLASSIFICATION: SECRET//NOFORN