Skip to content
Deep Analysis3 min read

Salt Typhoon in Europe: China Is Already Inside the Continent's Telecom Networks

8 April 2026|AEGIDA Research Team

On February 6, 2026, Norway's Police Security Service (PST) publicly confirmed what analysts had feared for months: Salt Typhoon — the cyber-espionage group operated by China's Ministry of State Security (MSS) — has compromised network devices in Norwegian organizations. It is the first public attribution of Salt Typhoon activity by a Nordic nation, and marks a turning point in Europe's perception of the Chinese cyber threat. PST Director General Beate Gangås stated that Norway "faces its most serious security situation since World War II."

Salt Typhoon: From America to Europe — Timeline of a Global Infiltration

Documented intrusions date back to at least 2019. In the United States, the campaign has been called "the worst telecom hack in American history": Salt Typhoon breached lawful intercept systems used to manage wiretap requests. In August 2025, the FBI revealed that Salt Typhoon breached at least 200 companies across 80+ countries. On August 27, 2025, CISA, NSA, FBI and other agencies issued a historic 37-page joint advisory.

Norway is the first Nordic country to publicly attribute an intrusion to Salt Typhoon. Security analysts warn that telecom operators in Sweden, Denmark, and Finland should assume they are on the same target list. The question is not whether Salt Typhoon is present in European networks — it is how deep it has already penetrated.

Attack Anatomy: How Salt Typhoon Penetrates Telecom Networks

PST specified that Salt Typhoon exploited vulnerabilities in network devices — routers, servers, and other equipment — to gain persistent access. This is the group's operational signature: it doesn't attack user endpoints but the infrastructure itself. Trend Micro identified at least 20 compromised organizations across telecoms, consulting, chemical, transportation, government, and nonprofit sectors.

  • Exploitation of vulnerabilities in edge network devices (routers, firewalls, VPN concentrators)
  • Persistent backdoors that survive device reboots
  • Silent lateral movement through operator core infrastructure
  • Access to lawful intercept systems and communications metadata
  • Prolonged exfiltration — in some cases active for years without detection
  • Targets: telecom, government, transportation, chemical, defense, hospitality sectors

The Most Disturbing Detail: Compromised Lawful Intercept Systems

What distinguishes Salt Typhoon is access to lawful intercept systems. In the United States, Salt Typhoon intercepted phone conversations of key officials, including President Donald Trump and Vice President JD Vance. If the same access level was achieved in European networks — and Norway's confirmation suggests it is plausible — the national security implications for every NATO member are enormous.

The joint CISA-NSA-FBI advisory (AA25-239A) of August 27, 2025 explicitly warns: PRC state-sponsored cyber threat actors are targeting networks globally, including telecommunications, government, transportation, hospitality, and military infrastructure. The 37-page advisory represents the most extensive inter-agency cooperation ever dedicated to a single threat actor.

Europe in the Crosshairs: From Norway to the Mediterranean

The Norwegian confirmation is just the tip of the iceberg. European telecom networks carry communications of NATO governments, EU institutions, military headquarters, and advanced research centers. For Chinese intelligence, compromising a single European telecom operator can provide access to a continuous stream of diplomatic, military, and commercial communications. The combination of Salt Typhoon (intelligence collection) and Volt Typhoon (pre-positioning for sabotage) represents a two-tier strategy with devastating potential.

Volt Typhoon: The Other Front — Pre-positioning for Sabotage

European governments have been formally warned that Volt Typhoon activity has been detected beyond North American networks. European OT infrastructure — power grids, pipelines, water treatment plants — is under sustained attack. Documented incidents involving energy operators in Germany, Denmark, Finland, and the Baltic states confirm that state-aligned threat actors are targeting physical systems.

IOCs and Attack Vectors

  • Exploitation of known vulnerabilities in edge network devices — Cisco routers, Fortinet firewalls, VPN concentrators
  • Anomalous traffic toward IPs associated with Chinese C2 infrastructure documented in advisory AA25-239A
  • Persistent backdoors in network device firmware surviving reboots and standard updates
  • Unauthorized access to lawful intercept systems and interception management platforms
  • Lateral movement via network management protocols (SNMP, SSH) with compromised credentials
  • Data exfiltration through encrypted channels toward IPs in Chinese cloud provider ranges

Operational Recommendations for European Organizations

  1. 1.Immediate audit of edge network devices: verify firmware, configurations, and backdoor presence on all internet-facing routers, firewalls, and VPN concentrators.
  2. 2.Management network segmentation: device management systems must be on segregated networks, unreachable from the internet. Access must require MFA and dedicated jump boxes.
  3. 3.Anomalous network traffic monitoring: implement NDR to identify suspicious communications toward external IPs, especially encrypted traffic toward unexpected IP ranges.
  4. 4.Lawful intercept access review: for telecom operators, complete audit of interception system access. Every access must be logged, monitored, and correlated with legitimate judicial requests.
  5. 5.Proactive threat hunting: use CISA AA25-239A IOCs to actively search for signs of prior compromise. Do not limit to recent logs — Salt Typhoon operates for years undetected.
  6. 6.Compromised device replacement plan: if compromise is identified, the device must be replaced, not just restored. Firmware-level backdoors can survive factory reset.
  7. 7.Critical communications on alternative channels: for diplomatic, military, and intelligence communications, use end-to-end encrypted channels independent of potentially compromised telecom infrastructure.

Conclusion: Europe Must Wake Up

Norway's February 2026 confirmation shattered the illusion that Salt Typhoon was an American problem. With 200+ breached companies across 80+ countries, operations active for at least seven years, and documented access to lawful intercept systems, Salt Typhoon represents the most extensive state-sponsored cyber-espionage operation ever conducted against global communications infrastructure. For every European telecom operator, the question is brutal: if China has been listening to our communications for years, what do they know that we don't know they know?

Primary sources: PST — Norwegian Police Security Service (2026 annual assessment, February 6, 2026), TechCrunch (March 9, 2026), FBI (August 2025), CISA-NSA-FBI Joint Advisory AA25-239A (August 27, 2025), Trend Micro (Salt Typhoon report, 2025-2026), Global Cyber Alliance ("Salt Typhoon Across the Internet" report), CyberScoop (FBI interview, 2026), The Meridiem (February 6, 2026).