
CISA and Five Eyes Issue Global Alert on Russian Center 16 and Chinese Salt Typhoon Infrastructure Infiltrations
A joint advisory warns of coordinated state-sponsored campaigns targeting edge networking devices across water and energy sectors, signaling a shift from espionage to pre-positioned sabotage.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2018-0171
- Source:
- Microsoft MSTIC
- Read Time:
- 5 min
Executive Summary
On July 21, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), in collaboration with the Five Eyes intelligence alliance and European partners, released a comprehensive update to a TLP:CLEAR advisory regarding the systemic targeting of critical infrastructure. The report details an unprecedented level of activity by Russian FSB-linked 'Center 16' (Ghost Blizzard) and Chinese-sponsored 'Salt Typhoon' (APT40). These actors are actively exploiting legacy networking hardware to gain persistent access to Operational Technology (OT) and Industrial Control Systems (ICS) in the United States, Europe, and Oceania. This intelligence comes in the wake of several 'near-miss' incidents at regional water treatment facilities where automated systems were temporarily disabled by unauthorized network configuration changes.
Threat Analysis
The intelligence community assesses that the current campaign represents a strategic shift in doctrine for both Russian and Chinese cyber operations. Unlike previous years where activities primarily focused on intellectual property theft, the 2025-2026 'Typhoon' and 'Blizzard' cycles demonstrate a prioritize on 'living-off-the-land' (LOTL) techniques intended for long-term persistence within the backbone of civilian infrastructure. By embedding within routers and switches that connect OT environments to the internet, these actors are creating dormant access points that could be activated to disrupt power distribution, water purification, and transportation logistics during periods of heightened geopolitical friction.
Technical Details
The primary vector for recent intrusions involves the exploitation of poorly configured Simple Network Management Protocol (SNMP) agents and known vulnerabilities in legacy edge devices, specifically targeting Cisco and Rockwell Automation hardware. Threat actors have been observed scanning for devices running SNMP v1/v2 with default community strings. Once access is gained, the actors execute commands to copy system configurations—often using filenames like 'config.bkp' or 'output.txt'—to actor-controlled virtual private servers (VPS). Recent analysis of the 'Salt Typhoon' toolset reveals the use of customized proxies and spoofed IP addresses to bypass Geo-IP filtering. Furthermore, actors are exploiting CVE-2018-0171 and more recent 2025-era vulnerabilities in industrial gateways to bridge the gap between IT and OT networks, allowing for the direct manipulation of Human-Machine Interfaces (HMI).
Attribution Assessment
Technical indicators and tactics, techniques, and procedures (TTPs) align with high confidence to Russian FSB Center 16, also known as Berserk Bear or Ghost Blizzard. This group has a documented decade-long history of energy sector probing. Simultaneously, the 'Salt Typhoon' activity is attributed with moderate confidence to the Chinese Ministry of State Security (MSS). While their methods overlap—specifically the focus on router configuration theft—their targets vary: Russian actors have focused heavily on Northern European power grids, while Chinese actors have concentrated on Pacific-based maritime logistics and Western US water utilities.
Implications
The presence of these actors in critical sectors poses a severe risk to public safety and national security. The ability to manipulate PLC (Programmable Logic Controller) logic or disrupt communication between grid sensors and control centers could lead to cascading blackouts or water contamination. The psychological impact of these penetrations also serves as a tool for coercion, demonstrating that civilian 'lifeline' services are vulnerable to remote disruption.
Recommendations
Encrygma recommends immediate action for all critical infrastructure operators. 1. Disable SNMP v1 and v2 in favor of SNMP v3 with strong encryption and authentication. 2. Implement strict micro-segmentation between IT and OT environments, ensuring no direct internet-facing exposure for industrial controllers. 3. Audit all edge networking devices for unauthorized configuration changes and external connections to unknown VPS ranges. 4. Patch all known vulnerabilities in industrial gateways and routers immediately. 5. Transition to out-of-band management for critical control systems to ensure operational continuity in the event of a primary network compromise.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Iranian-Linked APTs Escalate Cyber-Sabotage Campaign Against US and European Critical Infrastructure

Iran-Linked Cyber Actors Escalate Attacks on UK and US Critical Infrastructure

