Norway’s Police Security Service (PST) reported that the China-linked espionage actor tracked as Salt Typhoon compromised vulnerable network devices at multiple Norwegian organizations, marking Norway as the latest country to publicly confirm Salt Typhoon-related intrusions. The disclosure appeared in PST’s 2026 annual threat assessment, which characterized Norway’s security environment as exceptionally severe and highlighted foreign intelligence pressure.
PST assessed that China’s primary intelligence threat to Norway is in the cyber domain and warned that Chinese services are expected to continue mapping Norwegian digital infrastructure and collecting intelligence, alongside other hybrid tactics. Reporting also reiterated allied government assessments that Salt Typhoon has historically focused on telecommunications and other critical infrastructure internationally, including incidents in North America where U.S. officials said the campaign enabled interception of communications tied to senior political figures.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Norway’s Police Security Service (PST) disclosed in its 2026 annual threat assessment that Salt Typhoon had hit Norwegian organizations. PST said China poses a substantial cyber intelligence threat to Norway and warned that foreign intelligence services are increasingly combining cyber operations with traditional espionage and influence tactics.
The Chinese state-linked espionage campaign Salt Typhoon compromised vulnerable network devices at several Norwegian organizations to conduct espionage, according to Norway's later assessment. The activity was attributed by Norwegian authorities as likely being carried out on behalf of the Chinese government.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.