"They had access to everything, and what they could do within those networks was limited only by their own imaginations." — Mitch Rappard
Salt Typhoon and Volt Typhoon: distinct missions, shared origins
Many different government agencies and cybersecurity experts attribute both Salt Typhoon and Volt Typhoon to the Chinese Government. The two Advanced Persistent Threat (APT) groups surfaced in U.S. networks roughly "two or three years ago" when defenders first detected their presence. They have different operational goals: Salt Typhoon has focused on telecommunications networks in the U.S., penetrating providers' systems and exfiltrating call metadata, text messages, and other personal information; Volt Typhoon has targeted critical infrastructure such as utilities, water systems, ports, and "other essential government resources and services."
How they gained and sustained access: external IT systems and "living off the land"
Both groups entered and persisted not by exploiting telecom- or utility-specific zero-days but by attacking external-facing IT systems — routers, firewalls, and unpatched gateways. Once inside, they "lived off the land": performing activities that looked like normal network behavior rather than running obvious malware. The source documents that while inside networks these actors traded Secure Shell (SSH) keys, created new Linux accounts, and even established Generic Routing Encapsulation (GRE) tunnels for command-and-control traffic — techniques that helped them remain undetected for years.
Why private 5G networks and the Department of War are at risk
Government agencies and organizations within the Department of War (DoW) increasingly deploy private 5G networks to extend low-latency, high-bandwidth, and highly scalable connectivity to the tactical edge. Those networks carry "highly sensitive, mission-critical data and communications" between battlefield sensors and decision-makers. The article argues that a successful breach of a private 5G network could have cascading effects: shutting off power, sabotaging water supplies, disabling transportation hubs, revealing troop locations and movements, or enabling adversaries to inject spoofed intelligence — outcomes that could compromise civilian services or military operations, including causing "blue-on-blue incidents."
Responsibility sits with the deploying organization: segmentation, visibility, patching
The analysis stresses that the burden of ongoing upkeep and maintenance of a private 5G network "rests entirely on the shoulders of the agency or organization that deployed it." Key security activities named in the source are network segmentation, ensuring visibility for connected devices, and consistent update and patch management. Salt Typhoon and Volt Typhoon did not rely on exotic exploits; they succeeded by exploiting known vulnerabilities that "had been exposed and were supposed to have been (or should have been) patched." That lapse in basic hygiene enabled prolonged, deep access.
AI, vulnerability chaining, and the speed problem
The article warns that artificial intelligence amplifies the problem. New AI tools allow APT groups and other malicious actors to rapidly identify vulnerabilities and chain several low- to medium-severity flaws into novel, high-impact exploits. The result, as framed in the source, is increased vendor vulnerability announcements and the "commoditization of advanced attack capabilities" — meaning attackers can often exploit weaknesses faster than organizations can respond.
What this means for technologists, the DoW, and procurement leaders
- Technologists and security teams: They must treat private 5G deployments as fully owned networks — not managed services — with prioritized segmentation, device visibility, and disciplined patch programs to counter the "live off the land" tactics described.
- The Department of War and military organizations: Deployments that carry mission-critical telemetry and situational awareness must assume adversaries will attempt long-term, stealthy access; protecting those edge networks requires embedding security close to sensors and endpoints.
- Procurement and acquisition leaders: Because Salt Typhoon and Volt Typhoon exploited unpatched external-facing systems rather than niche telecom bugs, acquisition decisions should emphasize lifecycle support, patch cadence, and operational responsibilities rather than assuming vendor products alone guarantee security.
The drill-down in this source is stark: highly capable, state-attributed APTs have proven they can infiltrate and remain inside modern networks for years by exploiting routine vulnerabilities and using standard network tools. The prescription the author leaves us with is clear — build private 5G networks with a "security-led approach," push protections toward the edge, and recognize that prevention and upkeep are an ongoing operational task, not a one-time procurement box to check. The author, Mitch Rappard, says he will examine the specific tools and architectures to harden such networks in a subsequent piece.




