> For the complete documentation index, see [llms.txt](https://blog.r00t-hunter.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://blog.r00t-hunter.com/threat-actor-files/inside-the-typhoon-season-a-deep-dive-threat-intelligence-report-on-chinese-apt-intrusions-into-glo.md).

# Inside the Typhoon Season: A Deep-Dive Threat Intelligence Report on Chinese APT Intrusions into Glo

***

<figure><img src="/files/3zY4Srf2fkfxmCUIWruv" alt=""><figcaption></figcaption></figure>

### Executive Summary

Over the past eighteen months, a cluster of China-nexus threat actors publicly tracked under names like Salt Typhoon, Volt Typhoon, Liminal Panda, Gallium/Operation Soft Cell, and UNC2814 has conducted what may be the largest sustained espionage campaign against global telecommunications infrastructure ever documented. This is not a single hack. It is a portfolio of overlapping, multi-year intrusion sets, each with a different mission profile: signals-intelligence collection, protocol-level surveillance, and disruptive pre-positioning inside critical infrastructure.

This report consolidates confirmed, sourced incidents from 2024–2026, maps the threat actors and their tooling, and lays out concrete defensive priorities for telecom operators, MSSPs, and enterprise security teams whose organizations depend on carrier networks.

***

### 1. The Scale of the Problem, in Verified Numbers

The headline statistics are not marketing exaggeration they come directly from government advisories and named vendor disclosures:

* **53 confirmed victims across 42 countries**, with suspected infections in at least 20 more nations, in a campaign Google's Threat Intelligence Group (GTIG) and Mandiant attributed to a suspected PRC-nexus actor tracked as **UNC2814**, active since at least 2017 and disrupted in February 2026. Working with Mandiant, GTIG confirmed intrusions at 53 organizations across 42 countries, with suspected infections in at least 20 more, and identified the group as a suspected PRC-nexus actor that GTIG has tracked since 2017.
* **At least nine major US telecom carriers** including AT\&T, Verizon, T-Mobile, Lumen, Charter, Consolidated, and Windstream were compromised by **Salt Typhoon**, with US officials describing it as the worst telecom breach in the nation's history. Senator Mark Warner called it "the worst telecom hack in our nation's history," and by August 2025 the group had reportedly compromised 200-plus companies across 80 countries.
* **All four of Singapore's major telecom operators** Singtel, StarHub, M1, and Simba were breached by a China-linked actor Mandiant tracks as **UNC3886**, prompting an 11-month, 100-plus-person eviction effort dubbed Operation Cyber Guardian. The Cyber Security Agency of Singapore said UNC3886 embedded itself in the networks of all four major telecom providers, triggering an 11-month digital eviction effort involving more than 100 personnel from across government, military, intelligence, and industry. Singapore's own statement stops short of formally naming this "Salt Typhoon" it is tracked separately as UNC3886 though multiple outlets note the tradecraft closely mirrors the Salt Typhoon playbook.
* Chinese state actors have previously maintained access inside US critical infrastructure (the electric grid) for an estimated **300 days** before discovery a benchmark that illustrates how dwell time, not initial access, is the real defensive failure point in these campaigns.

***

### 2. Why Telecom Is Target Zero

Carriers sit at a structural chokepoint: every other sector's communications pass through them. Compromising a telecom operator gives an intelligence service simultaneous access to:

1. **Call Detail Records (CDRs) and metadata** who called whom, when, and from where, at population scale.
2. **Lawful intercept systems** surveillance infrastructure built for court-authorized wiretaps (in the US, mandated under CALEA) that becomes a ready-made espionage tool once an attacker controls it.
3. **SS7 and Diameter signaling protocols** the carrier-to-carrier "trust fabric" that supports roaming, SMS, and real-time location queries.
4. **Downstream access** a compromised carrier is a lateral pathway into every enterprise and government customer riding its network.

***

### 3. Threat Actor Profiles

#### 3.1 Salt Typhoon (aka GhostEmperor, FamousSparrow, Earth Estries, RedMike)

Salt Typhoon is the actor most responsible for the 2024–2026 US telecom crisis. In early October 2024, media outlets reported that PRC state-sponsored hackers had infiltrated US telecommunications companies, including internet service providers, and the group was investigated for compromising telecom firms, stealing customer communications and law-enforcement information, and targeting political figures.

Its expansion has continued well past the initial disclosure. Later reporting identified Charter Communications, Consolidated Communications, and Windstream as additional victims, widening a list that already included AT\&T, Verizon, T-Mobile, and Lumen Technologies, after US authorities had initially cited nine affected telecom firms. Even after the US government sanctioned individuals tied to the group, the intrusions continued. Threat intelligence firm Recorded Future, which tracks the group as "RedMike," reported observing Salt Typhoon breach five additional telecom firms between December 2024 and January 2025, including a US-based affiliate of a UK telecom provider, a US ISP, and carriers in Italy, South Africa, and Thailand, plus reconnaissance against Myanmar-based provider Mytel.

**Primary technical focus:** Cisco IOS XE devices. The group exploited two Cisco IOS XE vulnerabilities, CVE-2023-20198 and CVE-2023-20273, and attempted to compromise more than 1,000 Cisco devices globally, with particular focus on telecom-associated infrastructure. Once inside, the actor pivots toward the same lawful-intercept systems mandated for court-authorized wiretaps. Operators then pivot toward carrier surveillance equipment mandated for lawful interception, gaining access to call metadata, text messages, and in some cases live audio capture, prompting the FBI to urge Americans toward end-to-end encrypted messaging apps as a precaution.

**Toolset:** Demodex rootkit, GhostSpider backdoor, JumbledPath network-traversal tooling, and custom Cisco IOS XE implants.

**International reach:** By early 2026, the campaign had grown well beyond the US. A separately tracked but overlapping China-linked campaign UNC2814 hit more than 50 telecoms and government agencies across 42 countries as of February 2026, using Google Sheets as covert command-and-control infrastructure. Norway confirmed a Salt Typhoon-attributed attack, marking the first European government disclosure of the kind, and Singapore's CSA disclosed the UNC3886 intrusion into all four national carriers described above.

#### 3.2 Volt Typhoon Pre-Positioning for Crisis

Volt Typhoon has a fundamentally different mission from Salt Typhoon: not real-time intelligence collection, but durable, dormant footholds that could be activated during a future conflict. US agencies have been explicit about this framing. Government partners confirmed the group had compromised entities across communications, energy, transportation, and water/wastewater sectors in the US and its territories, and assessed that the PRC is positioning itself to conduct destructive cyberattacks that would jeopardize the physical safety of Americans in a crisis.

**Tradecraft:** Almost pure "living off the land" no custom malware, just native OS utilities. By using living-off-the-land techniques, PRC cyber actors blend in with normal system and network activity, evade network defenses, and minimize what shows up in standard logging, which CISA said requires behavioral analytics and proactive hunting rather than signature detection to catch.

**Covert infrastructure the KV-Botnet:** The FBI disrupted a botnet the actors used to mask operations, built from hundreds of compromised small office/home office routers infected with KV-Botnet malware, which obscured the intrusions' Chinese origin and provided a covert relay layer for follow-on attacks in the US and elsewhere. The botnet has since been reconstituted more than once, and 2026 reporting shows the group is still active. A 2026 Dragos report confirmed Volt Typhoon remains embedded in US utilities, with an initial-access cluster still targeting edge devices particularly Fortinet and Ivanti appliances and documented a confirmed intrusion through an unpatched FortiGate firewall near Guam's Andersen Air Force Base and nearby naval installations. Officials have not minced words about the stakes: at a January 2024 hearing, then-CISA Director Jen Easterly described the threat scenario as "Everything Everywhere, All at Once," warning of simultaneous failures across telecom, water, transport, and power.

#### 3.3 Liminal Panda The Protocol-Level Specialist

Liminal Panda (overlapping with the earlier-misattributed "LightBasin"/UNC1945 cluster) is arguably the most telecom-native of all the groups profiled here it doesn't just attack telecom companies, it speaks their protocols. CrowdStrike assesses the adversary conducts intrusion activity using protocols that support mobile telecommunications, including emulating GSM protocols to enable command-and-control, and building tooling to retrieve mobile subscriber information, call metadata, and text messages.

**Custom tooling:** The group has used SIGTRANslator, a Linux ELF binary built to send and receive data over SIGTRAN protocols, alongside CordScan and PingPong, in combination with the open-source TinyShell backdoor and a publicly available SGSN emulator (sgsnemu) that tunnels command-and-control traffic through GPRS network access points.

**Attribution nuance:** CrowdStrike is notably cautious here this is a low-confidence China-nexus assessment, not a certainty. CrowdStrike's China-nexus assessment is made with low confidence, based on factors such as targeting concentrated in Belt and Road Initiative countries and use of a Pinyin string ("wuxianpinggu507," meaning "wireless evaluation 507") as an XOR key and proxy password that individually do not strongly indicate attribution. A separate outlet notes the ambiguity explicitly: CrowdStrike stated that definitive attribution to a specific Chinese state-backed entity remains inconclusive due to a lack of direct evidence linking Liminal Panda to known government-affiliated organizations, despite tooling and process overlaps with other China-nexus groups such as Sunrise Panda and Horde Panda.

#### 3.4 Gallium / Operation Soft Cell

Gallium (Granite Typhoon) is the earliest well-documented case of large-scale telecom-focused Chinese espionage, first exposed publicly around 2019 under the name "Operation Soft Cell." It pioneered the playbook later groups refined: compromise internet-facing enterprise servers (historically Microsoft Exchange and Oracle WebLogic), drop web shells, and pivot into billing and subscriber systems to harvest CDRs on individuals of interest. Its tooling China Chopper, PingPull, PoisonIvy sits within the broader "shared malware economy" discussed below. Salt Typhoon has itself been described by some researchers as an evolution of, or closely linked to, the Gallium cluster. One 2026 analysis explicitly frames Salt Typhoon as linked to the broader group known as GALLIUM.

#### 3.5 UNC2814 The Google Sheets Campaign

The most recently disrupted and, in some ways, most instructive campaign for defenders came from UNC2814, a group Google says it has tracked since 2017. The campaign relied on a newly identified backdoor, GRIDTIDE, designed to blend malicious traffic with legitimate cloud API activity by using Google Sheets as a covert command-and-control channel. The data targeted was squarely personal and identity-related: in at least one case GRIDTIDE was deployed on systems containing personally identifiable information, including full names, phone numbers, dates and places of birth, voter ID numbers, and national ID numbers. Google's response is itself a useful case study in coordinated takedown: GTIG terminated all attacker-controlled Cloud Projects to cut off GRIDTIDE backdoor access, took down known UNC2814 domains and infrastructure, revoked attacker accounts and Google Sheets API access, notified and supported victim organizations, and released indicators of compromise dating back to 2023.

***

### 4. Beyond Malware: The SS7/Diameter Surveillance Layer

Not every actor in this space needs to compromise a network at all some abuse the *design* of the global telecom signaling fabric itself. A landmark April 2026 Citizen Lab report, "Bad Connection," documented this in unprecedented technical detail. The investigation uncovered two sophisticated telecom surveillance campaigns and, for the first time, linked real-world attack traffic directly to mobile operator signalling infrastructure, exposing how suspected commercial surveillance vendors exploit the SS7 and Diameter protocols that connect the world's mobile operators.

The mechanics are protocol-native, not malware-based: the campaigns shifted between SS7, the signaling protocol underpinning 3G, and Diameter, used for 4G and most 5G networks and although Diameter was designed to be more secure, the FCC opened a probe into vulnerabilities in both protocols in 2024. Citizen Lab describes the underlying flaw as structural rather than incidental: these vulnerabilities are not the result of software bugs or misconfigurations, but are inherent to a global telecommunications design built around a thousand-plus interconnected operators whose roaming agreements and signaling protocols were built to prioritize efficiency and trust over verification.

The operators behind these campaigns don't hack into a carrier they operate through one. Two surveillance vendors posed as legitimate cellular carriers, using an Israeli telecom, a British provider, and a Channel Islands operator as entry points to track targets across multiple countries over several years. One identified entry point drew direct scrutiny: the report names Israeli operator 019Mobile as the entry point relied on in the first campaign, which attempted SS7 exploitation before falling back to Diameter abuse when needed. Researchers were careful about attribution to nation-states in this report the emphasis is on the commercial surveillance vendor ecosystem rather than a specific government's hacking unit but the operational overlap with the same signaling infrastructure Chinese APT groups (particularly Liminal Panda) are known to target is a critical point for defenders: **SS7/Diameter abuse is now a multi-actor, multi-nation risk, not a single-APT problem.**

***

### 5. Common Tactics, Techniques, and Procedures Across the Ecosystem

#### 5.1 Edge Device Exploitation

The dominant initial-access vector in 2025–2026 across nearly every group profiled here is exploitation of internet-facing network appliances the exact hardware sitting at a telecom's perimeter. Confirmed exploited product lines include Cisco IOS XE (Salt Typhoon), FortiGate firewalls (Volt Typhoon, UNC3886), Ivanti Connect Secure, Juniper Junos OS, and VMware ESXi/vCenter (UNC3886). The Singapore intrusions allegedly involved zero-days in the telcos' firewalls combined with rootkits for persistence, and Trend Micro noted the actor's long history of exploiting networking and enterprise gear including Fortinet, Juniper, Ivanti SecureConnect, and VMware ESXi and vCenter.

#### 5.2 Covert Relay Infrastructure ORB Networks

Rather than using easily-blocklisted infrastructure, several groups now route operations through large botnets of compromised SOHO routers and IoT devices so-called Operational Relay Box (ORB) networks. A joint April 2026 advisory from CISA, FBI, NSA, NCSC-UK, and eleven other international cyber agencies described a major shift in China-nexus tradecraft toward large-scale covert networks of compromised SOHO routers, IoT devices, and smart devices, naming both Volt Typhoon's KV-Botnet and Flax Typhoon's Raptor Train botnet, the latter having infected more than 200,000 devices worldwide in 2024.

#### 5.3 A Shared Malware Economy

Chinese APT clusters operate on what amounts to a shared toolkit model, which complicates attribution and defense alike: ShadowPad (used across APT41, APT10, APT27, APT40, and Mustang Panda), PlugX (in active development for over a decade, used by at least eight distinct clusters), China Chopper (the most common web shell across the entire ecosystem), and HyperBro (most associated with APT27 but seen in adjacent clusters).

#### 5.4 Living Off the Land

Volt Typhoon is the clearest exemplar, but the technique is spreading: intrusions conducted almost entirely with native Windows utilities (netsh, wmic, ntdsutil, PowerShell) rather than custom malware, leaving minimal signature-based forensic trail.

***

### 6. Real-World Impact

* **Surveillance of court-authorized wiretap systems.** Salt Typhoon's access to CALEA-mandated lawful intercept infrastructure means the same systems built to protect legal due process became an espionage asset reportedly including access to metadata from over a million users and recorded calls involving 2024 presidential campaign staff.
* **Population-scale metadata collection**, enabling social-network mapping of intelligence targets from CDRs and subscriber databases.
* **Persistent, crisis-ready access** inside critical infrastructure via Volt Typhoon-style pre-positioning, with FBI leadership warning of coordinated disruption across sectors during a future crisis.
* **Location-tracking-as-a-service** via SS7/Diameter abuse, sold commercially and used against government and civilian targets alike, per Citizen Lab.
* **Long dwell times that erode accountability.** Chinese actors have previously remained inside US critical infrastructure for an estimated 300 days before discovery, and telecom dwell times measured in years are not uncommon meaning the true scope of data exfiltrated in many of these campaigns may never be fully known.

***

### 7. Defensive Priorities for Telecom and Enterprise Security Teams

1. **Patch internet-facing appliances within 48 hours of critical CVE disclosure**, with special priority on Cisco IOS XE, Ivanti, Fortinet, Juniper, and VMware ESXi/vCenter the products most consistently exploited across every group in this report.
2. **Retire end-of-life edge devices** from production networks. ORB networks are built almost entirely on unsupported SOHO routers.
3. **Monitor inbound connections from residential broadband and SOHO IP space**, not just known-malicious infrastructure ORB relay traffic is specifically designed to look local.
4. **Enable comprehensive PowerShell and command-line logging** (Script Block Logging, Module Logging) to catch living-off-the-land activity that leaves no malware signature.
5. **Hunt for DLL sideloading and signed-binary execution from non-standard paths** (%APPDATA%, %TEMP%) a pattern seen across Mustang Panda, APT10, APT41, and APT27.
6. **Treat SS7/Diameter signaling security as a first-class problem**, not a legacy afterthought. Citizen Lab's findings show active real-world exploitation years after these protocols' weaknesses became public knowledge.
7. **Harden identity and cloud management planes.** UNC2814's use of the Google Sheets API as C2 shows attackers increasingly targeting SaaS trust relationships and API tokens rather than endpoints directly.
8. **Segment OT and telecom signaling networks from enterprise IT**, since Volt Typhoon's pre-positioning specifically targets this boundary.
9. **Validate detection coverage against shared malware families** ShadowPad, PlugX, HyperBro, China Chopper since a single detection rule here can intercept multiple threat groups at once.
10. **Assume dwell time, not zero-day discovery, is the default state.** Behavioral analytics and continuous control validation matter more than perimeter hardening alone.

***

### 8. Source List

* Google Threat Intelligence Group / Mandiant [UNC2814 GRIDTIDE disruption report](https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html) (via The Hacker News, Feb 25, 2026)
* CSO Online [UNC2814 42-country campaign](https://www.csoonline.com/article/4137834/china-linked-hackers-used-google-sheets-to-spy-on-telecoms-and-governments-across-42-countries.html)
* BleepingComputer [UNC2814 telecom/government breach](https://www.bleepingcomputer.com/news/security/chinese-cyberspies-breached-dozens-of-telecom-firms-govt-agencies/)
* CSO Online [Additional Salt Typhoon US telecom victims](https://www.csoonline.com/article/3632044/more-telecom-firms-were-breached-by-chinese-hackers-than-previously-reported.html)
* TechCrunch [Salt Typhoon continues despite sanctions](https://techcrunch.com/2025/02/13/chinas-salt-typhoon-hackers-continue-to-breach-telecom-firms-despite-us-sanctions)
* Congress.gov / CRS [Salt Typhoon federal response](https://www.congress.gov/crs-product/IF12798)
* BleepingComputer [Singapore telcos breach, UNC3886](https://www.bleepingcomputer.com/news/security/chinese-cyberspies-breach-singapores-four-largest-telcos/)
* The Register [Singapore 11-month eviction operation](https://www.theregister.com/2026/02/10/singapore_telco_espionage)
* TechCrunch [Singapore official confirmation](https://techcrunch.com/2026/02/10/singapore-china-backed-hackers-targeted-largest-phone-companies-salt-typhoon/)
* Risky Business Media [Singapore telco breach details](https://risky.biz/risky-bulletin-chinese-cyber-spies-breached-all-of-singapores-telcos/)
* CISA [Joint advisory: PRC state-sponsored actors and critical infrastructure](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a)
* CISA [Original Volt Typhoon advisory announcement](https://www.cisa.gov/news-events/news/us-and-international-partners-publish-cybersecurity-advisory-peoples-republic-china-state-sponsored)
* Microsoft Security Blog [Volt Typhoon technical analysis](https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/)
* Kraven Security [Volt Typhoon 2026 threat profile](https://kravensecurity.com/volt-typhoon-threat-profile/)
* GovPing [CISA/FBI/NSA joint ORB network advisory](https://changeflow.com/govping/data-privacy-cybersecurity/joint-advisory-covers-volt-typhoon-flax-typhoon-threat-actor-2026-04-23)
* CrowdStrike [Unveiling Liminal Panda](https://www.crowdstrike.com/en-us/blog/liminal-panda-telecom-sector-threats/)
* CrowdStrike [LightBasin/Liminal Panda technical report](https://www.crowdstrike.com/en-us/blog/an-analysis-of-lightbasin-telecommunications-attacks/)
* The Hacker News [Liminal Panda SIGTRAN/GSM tooling](https://thehackernews.com/2024/11/china-backed-hackers-leverage-sigtran.html)
* Infosecurity Magazine [Liminal Panda BRI targeting, attribution caveats](https://www.infosecurity-magazine.com/news/chinese-apt-targets-telecoms-bri/)
* The Citizen Lab ["Bad Connection" report](https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/)
* CyberScoop [Citizen Lab SS7/Diameter coverage](https://cyberscoop.com/surveillance-campaigns-use-commercial-surveillance-tools-to-exploit-long-known-telecom-vulnerabilities/)
* TechCrunch [Citizen Lab surveillance vendors report](https://techcrunch.com/2026/04/23/surveillance-vendors-caught-abusing-access-to-telcos-to-track-peoples-phone-locations-researchers-say/)

***

### 9. Suggested Category / Taxonomy for This Post

For a blog that already runs topics like *Cellphones, Cyberwar, Cyberwarrior, Hacking, Mobile Hacking, Pentesting, SDR/Signals Intelligence*, this piece fits best under a **new dedicated category** rather than being folded into an existing generic one, since it's actor/geopolitics-driven threat intel rather than a how-to tutorial. Suggested options, best fit first:

1. **"Nation-State Threats"** (or **"APT Intelligence"**) a category purely for state-actor profiles, campaign trackers, and attribution reporting (Salt Typhoon, Volt Typhoon, Liminal Panda, etc.), distinct from general "Hacking" how-tos.
2. **"Telecom & SIGINT Security"** narrower, pairs naturally with your existing "SDR/Signals Intelligence" tag if you want future SS7/Diameter/GSM-focused posts to live together.
3. **"Cyberwarfare & Geopolitics"** broadest option if you want to bucket this alongside pre-positioning/critical-infrastructure and policy-adjacent posts (CISA advisories, sanctions, congressional response) rather than pure technical intrusion analysis.

Given the post's structure (actor profiles + TTPs + defensive guidance), **"Nation-State Threats / APT Intelligence"** is the cleanest fit, with cross-tagging into your existing "Cyberwar" and "SDR/Signals Intelligence" categories for discoverability.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://blog.r00t-hunter.com/threat-actor-files/inside-the-typhoon-season-a-deep-dive-threat-intelligence-report-on-chinese-apt-intrusions-into-glo.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
