Salt Typhoon Cyber Espionage Campaign Targeting U.S. Critical Infrastructure
U.S. officials and cybersecurity experts have highlighted the ongoing threat posed by nation-state actors, particularly the Chinese-linked group known as Salt Typhoon, which has conducted widespread cyber intrusions targeting critical American infrastructure. These campaigns have focused on stealing intellectual property, surveilling government officials, and pre-positioning within essential networks such as airports, hospitals, water treatment facilities, and telecom providers, with the intent to disrupt services or gather intelligence at a time of their choosing. The persistence and sophistication of these operations underscore the urgent need for coordinated defense efforts between government agencies and the private sector, as most critical infrastructure is privately owned or operated.
Recent incidents attributed to Salt Typhoon include the compromise of multiple U.S. telecom networks, with attackers maintaining access for nearly a year before detection. These breaches exemplify the evolving nature of hybrid and cross-domain threats, where cyber intrusions can cascade into physical and reputational risks. Security leaders are being urged to adopt new, asymmetric approaches to risk management, breaking down traditional silos and ensuring that intelligence and response capabilities keep pace with the rapidly changing threat landscape.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
1 event from the most recent confirmed update back to the earliest known activity.
Story first reported
Initial story creation
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


