Norwegian authorities publicly attributed a series of intrusions and espionage activity against multiple Norwegian organizations to Salt Typhoon, a China-linked threat actor assessed to be operating on behalf of Chinese government interests. Norway’s Police Security Service (PST) said the actor gained access by compromising vulnerable network devices, marking one of the clearest acknowledgements from a European government that the campaign has extended beyond previously reported activity in North America.
Norway’s assessment described Salt Typhoon as an example of how private Chinese cybersecurity contractors can augment Chinese security and intelligence services, and warned that Chinese cyber operations will remain a major intelligence threat to Norway in 2026. Reporting also tied Salt Typhoon to a broader pattern of stealthy targeting of critical infrastructure, including past allegations of compromises of telecommunications providers in the U.S. and Canada where communications of senior politicians were reportedly intercepted, increasing pressure on telecom operators to harden network security.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
In its threat assessment, Norway’s Police Security Service said Chinese cyber operations would remain one of the country’s most significant intelligence threats in 2026. The assessment highlighted growing use of exploited routers, servers, and other network devices for persistent access, and linked Salt Typhoon to private Chinese cybersecurity firms.
Norway publicly disclosed that the China-linked Salt Typhoon cyberespionage group compromised multiple Norwegian organizations by exploiting vulnerable network devices. The attribution came from Norway’s Police Security Service, which said the activity was part of espionage operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.