salttyphoon

NODE_ID: SaltTyphoon // STATUS: ACTIVE

Salt Typhoon / APT28 (GRU)

ORGANISATION INTERNATIONAL

01 Executive_Summary

State-sponsored cyber threat actors (PRC MSS / Russian GRU). Infiltrated U.S. ISPs and Max Planck Institute to map the Gray Track human network.

02 Deep_Dive_Intelligence

Intelligence Summary: Salt Typhoon / APT28 (GRU)

Classification: Composite state-sponsored cyber threat actor designation encompassing PRC Ministry of State Security (MSS) ISP infiltration operations ('Salt Typhoon') and Russian military intelligence (GRU Unit 26165 / APT28) cyber-kinetic targeting infrastructure.

Operations:

  • Infiltrated major U.S. Internet Service Providers to harvest communications metadata
  • Penetrated Max Planck Institute networks to map the 'human connective tissue' of the Gray Track academic ecosystem
  • Generated sociogram targeting packages used to identify and prioritize high-value human capital nodes
  • Provided Command and Control (C2) infrastructure and weaponized Emotet malware to kinetic operators

Impact: The Salt Typhoon sociogram mapping directly enabled the identification and targeting of Dr. Nuno Loureiro as a critical single-point-of-failure.

03 Network_Linkage

  • Cláudio Valente — Cyber-financial targeting support for kinetic strike
  • Dr. Nuno Loureiro — Primary target identified via sociogram mapping
  • Max Planck Institute — Infiltrated to map Gray Track academic network
  • PRC / MSS — Salt Typhoon operational sponsor
  • GRU Unit 26165 — APT28 C2 infrastructure provider
SECURE_HASH: 711E04C3
LAST_UPDATED: 2026-06-02
CLASSIFICATION: SECRET//NOFORN