Listen to this Post

A Growing Cybersecurity Standoff Between the US and China
A new wave of cyber threats tied to China has caught the attention of the FBI and cybersecurity experts worldwide. The hacking group known as Salt Typhoon, believed to be backed by the Chinese government, has managed to infiltrate critical telecommunications networks across the United States. Although these attackers are now said to be “largely contained” and “dormant” within affected systems, their ability to pivot from espionage to destructive operations raises serious concerns for national security. According to Brett Leatherman, the FBI’s newly appointed head of the Cyber Division, the threat from Salt Typhoon remains significant, despite a lack of current activity. His department is currently focused on resilience and support for affected companies, while planning future operations to deter and penalize those behind the attacks. This article explores the current status of Salt Typhoon’s presence in U.S. infrastructure, compares it with similar groups like Volt Typhoon, and examines the wider geopolitical and cyber implications of the breach.
Chinese Hackers Embedded in US Telecom Networks
The Salt Typhoon hacking campaign, originating from China, targeted at least nine U.S. telecommunications companies, raising alarms at the highest levels of cybersecurity enforcement. FBI Cyber Division chief Brett Leatherman disclosed that while the hackers are no longer actively exfiltrating data, they are still present in the networks, “locked” in and potentially capable of pivoting toward sabotage. Despite the dormant state, their ability to move from spying to destructive actions remains a dangerous possibility.
Unlike their counterparts Volt Typhoon, who are believed to be prepositioned across U.S. critical infrastructure in anticipation of geopolitical conflict, Salt Typhoon initially focused on espionage. Yet, as Leatherman points out, the distinction is more technical than practical. Access gained for intelligence purposes can easily be repurposed to carry out damaging cyberattacks. This dual-purpose threat underscores the need for continuous monitoring and stronger cyber defense strategies.
Collaboration has been key. The U.S. has worked closely with European and North American allies, sharing technical details and breach methodologies to prevent similar compromises abroad. Leatherman insists that every affected company in the U.S. was engaged with the FBI at a pace comfortable to the victims, countering criticism that the federal government didn’t do enough to assist them during the breach.
Still, the effort to fully remove Salt Typhoon from these telecom networks remains ongoing. The longer hackers remain embedded, the more persistence mechanisms they can deploy—creating multiple backdoors and footholds that are incredibly difficult to root out. As Leatherman notes, these embedded threats evolve over time, adapting to avoid detection and removal.
Looking ahead, the FBI is prioritizing resilience and deterrence, bolstering cybersecurity for victims while seeking additional attribution data to justify future offensive operations. Joint sequenced operations are on the table, but they require solid intelligence to proceed.
In parallel, the FBI is also addressing cyber threats from North Korean IT workers running fraudulent schemes. Although their techniques remain consistent, the risks they pose—particularly from insider access—could lead to serious breaches of intellectual property or even serve as brokers for Chinese actors to infiltrate new networks.
Leatherman warned of a troubling shift. The threat actors could move toward theft of intellectual property, or serve as intermediaries, selling access to sensitive systems to other adversaries. Such a move would transform passive espionage into active, aggressive cybercrime with far-reaching consequences for U.S. security, innovation, and business competitiveness.
What Undercode Say:
Embedded Threats Still Pose a High Risk Despite FBI Containment
The FBI’s recent containment of Salt Typhoon may seem like a victory, but it’s merely a temporary pause in a long cyber battle. Dormant hackers, especially those with nation-state affiliations, can lurk silently in systems for years, waiting for the right moment to strike. The fact that these actors are still present in the networks—even if inactive—represents a ticking time bomb.
Salt Typhoon’s use of access for both espionage and destructive capability indicates a shift in modern cyber warfare. It’s no longer about choosing between spying and sabotage—adversaries like China are preparing for both, simultaneously embedding tools for intelligence gathering and potential system shutdowns.
The
Leatherman’s focus on resilience and victim support is essential. However, preventing future breaches requires moving beyond incident response. Investment in zero-trust architectures, tighter supply chain controls, and AI-driven threat detection will be key pillars of defense.
The comparison to Volt Typhoon is also significant. Both groups demonstrate China’s increasing focus on embedding within critical infrastructure, which may include water systems, power grids, and transportation. These are strategic footholds for geopolitical leverage or potential wartime disruption.
The FBI’s transparency in disclosing nine affected telecoms is commendable, yet the true number could be higher, particularly if some companies haven’t yet detected breaches. Collaboration with Europe and North America is a strong signal that the U.S. recognizes the global nature of cyber threats, but domestic readiness must remain a top priority.
North Korean threats add another layer of complexity. Their stable infiltration methods make them harder to detect and respond to, especially when they pose as legitimate IT workers. The insider threat, when paired with geopolitical motives, creates a blend of economic and national security risks that traditional cybersecurity frameworks aren’t always equipped to handle.
What’s most concerning is the future trajectory of these actors. If Chinese hackers pivot to intellectual property theft or sell access to third parties, it would open up a cybercrime marketplace ripe for exploitation by other adversaries like Iran or Russia. This evolution would create secondary risks across sectors like biotech, aerospace, and AI—further compromising U.S. innovation and security.
The Salt Typhoon case also reveals gaps in attribution capacity. Without rock-solid digital forensics, many of these operations can’t be tied to state actors definitively, delaying or preventing retaliatory actions. This underscores the urgent need for more cyber intelligence alliances and data-sharing platforms that can accelerate attribution and response.
Finally, while the FBI’s engagement with victim companies was reported as proactive, public-private partnerships still face trust issues. For long-term resilience, fostering deeper collaboration and transparent threat sharing will be crucial. After all, the front lines of modern warfare are increasingly digital, and no single agency or company can win the battle alone.
🔍 Fact Checker Results:
✅ Salt Typhoon is confirmed to be a Chinese cyber-espionage group with dormant access to U.S. telecom networks
✅ The FBI has verified engagement with all known victim companies during the breach response
❌ Full removal of Salt Typhoon from all compromised systems has not yet been achieved
📊 Prediction:
Salt Typhoon’s dormant presence suggests a long-term strategy by Chinese actors to embed quietly within U.S. critical infrastructure. If geopolitical tensions escalate, this group could quickly transition to offensive operations. Over the next 12 months, expect a shift in U.S. cyber policy toward more proactive threat neutralization, including sanctions and international cyber task forces. The battle is no longer just about defense — it’s about preventing silent invaders from becoming saboteurs.
References:
Reported By: cyberscoop.com
Extra Source Hub:
https://www.github.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




