Salt Typhoon / APT28 (GRU)
Salt Typhoon / APT28 (GRU)
01 Executive_Summary
State-sponsored cyber threat actors (PRC MSS / Russian GRU). Infiltrated U.S. ISPs and Max Planck Institute to map the Gray Track human network.
03 Deep_Dive_Intelligence
Intelligence Summary: Salt Typhoon / APT28 (GRU)
Node Identity: Salt Typhoon (also known as APT28, Fancy Bear, or Strontium) is a state-sponsored cyber threat actor group assessed as operating under dual sponsorship from the Chinese Ministry of State Security (MSS) and Russian military intelligence (GRU). The group infiltrated U.S. Internet Service Providers (ISPs) and the Max Planck Institute to map the Gray Track human network supporting FRC/plasma weapons research.
Strategic Relevance: Salt Typhoon's ISP infiltration campaign represents the intelligence preparation phase for adversary kinetic operations against the FRC research community. By compromising U.S. telecommunications infrastructure, the group harvested sociogram data mapping the professional and personal connections of key researchers, program managers, and military officers involved in compact fusion and exotic propulsion programs. This targeting data directly enabled the Valente assassination of Dr. Nuno Loureiro in December 2025. The Max Planck Institute infiltration indicates the campaign extended beyond U.S. borders to map the international FRC research collaboration network.
Technical Focus / Capabilities:
- ISP Infiltration: Compromised U.S. telecommunications infrastructure to intercept communications and map social networks of FRC researchers and defense personnel.
- Sociogram Harvesting: Generated targeting packages from intercepted communications data, identifying key nodes in the Gray Track human network and their interpersonal connections.
- Max Planck Institute Breach: Infiltrated European fusion research institution to map international FRC collaboration networks and identify dual-use technology transfer pathways.
- C2 Infrastructure: Maintained command and control infrastructure overlapping with weaponized Emotet malware, providing deniable operational support for kinetic operators like Valente.
- Cryptocurrency Infrastructure: Darknet escrow nodes for Monero (XMR) payments to kinetic operators, creating a financial pipeline linking cyber intelligence to kinetic operations.
Network Linkage: Salt Typhoon operates as the cyber-intelligence enabler for adversary kinetic actions against the FRC human network. The ISP infiltration campaign provided the targeting data that enabled Valente's strike against Loureiro. The C2 infrastructure overlap with Valente's operational network confirms the cyber-to-kinetic pipeline. PRC MSS operational sponsorship provides resources and political cover, while Russian GRU involvement provides tradecraft and deniable execution capabilities. The Max Planck Institute breach extends the intelligence campaign to European allies, potentially identifying FRC knowledge transfer pathways through international collaboration. The group's activities represent a systematic adversary effort to map, target, and neutralize the human capital underpinning U.S. compact fusion and exotic propulsion programs.
04 Network_Linkage
Salt Typhoon's network position as cyber-intelligence enabler for adversary kinetic operations:
- Cláudio Valente: Provided cyber-financial targeting support and C2 infrastructure for the Loureiro assassination. Emotet malware overlap confirmed operational connection.
- PRC (MSS): Operational sponsor. Provides resources and political cover for ISP infiltration and sociogram harvesting campaigns.
- U.S. ISPs: Infiltrated telecommunications infrastructure to map Gray Track human network connections and generate targeting packages.
- Max Planck Institute: Breached to map international FRC research collaboration networks and identify technology transfer pathways.
- Dr. Nuno Loureiro: Indirect target. Sociogram data from ISP infiltration enabled Valente's targeting package.
- Darknet Escrow Network: Monero (XMR) payment infrastructure linking cyber intelligence operations to kinetic operator funding.
- Gray Track Human Network: Primary intelligence target. Mapping connections between researchers, program managers, and military officers enables systematic targeting.
05 Related_Entities (2)
05b Related_Topics (3)
07 Key_Findings
- ▸ Classification: Composite state-sponsored cyber threat actor designation encompassing PRC Ministry of State Security (MSS) ISP infiltration operations ('Salt Typhoon') and Russian military intelligence (GRU Unit 26165 / APT28) cyber-kinetic targeting infrastructure.
- ▸ Infiltrated major U.S. Internet Service Providers to harvest communications metadata
- ▸ Penetrated Max Planck Institute networks to map the 'human connective tissue' of the Gray Track academic ecosystem
- ▸ Generated sociogram targeting packages used to identify and prioritize high-value human capital nodes
- ▸ Provided Command and Control (C2) infrastructure and weaponized Emotet malware to kinetic operators
08 Intelligence_Analysis
Intelligence Summary: Salt Typhoon / APT28 (GRU)
Classification: Composite state-sponsored cyber threat actor designation encompassing PRC Ministry of State Security (MSS) ISP infiltration operations ('Salt Typhoon') and Russian military intelligence (GRU Unit 26165 / APT28) cyber-kinetic targeting infrastructure.
Operations:
- Infiltrated major U.S. Internet Service Providers to harvest communications metadata
- Penetrated Max Planck Institute networks to map the 'human connective tissue' of the Gray Track academic ecosystem
- Generated sociogram targeting packages used to identify and prioritize high-value human capital nodes
- Provided Command and Control (C2) infrastructure and weaponized Emotet malware to kinetic operators
Impact: The Salt Typhoon sociogram mapping directly enabled the identification and targeting of Dr. Nuno Loureiro as a critical single-point-of-failure.
10 FAQ
What is Salt Typhoon / APT28 (GRU)? ▾
What role does Salt Typhoon / APT28 (GRU) play in the research network? ▾
What evidence supports the Salt Typhoon / APT28 (GRU) assessment? ▾
How does Salt Typhoon / APT28 (GRU) connect to other entities in the network? ▾
Where is Salt Typhoon / APT28 (GRU) located or active? ▾
What is Salt Typhoon / APT28 (GRU)'s mission and strategic role? ▾
Who are the key personnel associated with Salt Typhoon / APT28 (GRU)? ▾
What is Salt Typhoon / APT28 (GRU)'s strategic position in the defense ecosystem? ▾
How does Salt Typhoon / APT28 (GRU) fit into the broader intelligence network? ▾
What external sources document Salt Typhoon / APT28 (GRU)? ▾
Verified_Primary_Sources 5 SOURCES
Geographic_Data
Type: organisation
Region: main
Last updated: Research database snapshot