Chinese Hacking Group Salt Typhoon Suspected of Spying on Telecom Networks in Canada

Great white shark swimming in deep blue ocean water

Around the same time last year, media outlets widely reported that a Chinese state-sponsored hacking group had potentially infiltrated the telecommunication infrastructure of the United States. The speculation gained traction when a senior information and broadcasting official acknowledged that at least 12 telecom circles across the U.S. appeared to have been compromised by cybercriminals allegedly backed by Beijing.

Now, new intelligence points to a similar breach targeting Canada’s telecom sector. According to cybersecurity researchers, the same threat actor — a China-backed hacking group known as Salt Typhoon — has been conducting surveillance and cyber-espionage on Canadian communication networks for at least two years.

In response, Chinese officials have dismissed these claims as unfounded, reiterating their longstanding stance that China does not engage in cyber warfare. However, the denials do little to reassure global cybersecurity analysts, especially as more revelations surface.

Cyber Tensions Rising: China Allegedly Targeting Russian Defense Systems

Adding a surprising twist to the geopolitical cyber landscape, reports from Russian sources have alleged that Chinese hackers recently attempted to breach sensitive Russian defense systems. This move is seen by some analysts as a covert signal of Beijing’s shifting stance in the ongoing Russia-Ukraine conflict — potentially leaning toward support for Ukraine.

Security experts at Taiwan-based cybersecurity firm TeamT5 have identified two advanced persistent threat (APT) groups from China — APT31 (also known as Zirconium or Judgment Panda) and APT27 (widely known as Mustang Panda or Sanyo) — as being actively involved in spying operations targeting Russia. These groups were reportedly focused on infiltrating critical Russian technologies, including nuclear capabilities and submarine programs, with the goal of gathering strategic intelligence.

End of a No-Hack Pact Between Allies?

For years, Chinese President Xi Jinping and Russian President Vladimir Putin were believed to have maintained a tacit agreement to avoid cyber hostilities. Their nations were viewed as digital allies, refraining from launching cyberattacks against one another. However, the latest findings by TeamT5 suggest that this unspoken digital truce may be unraveling.

Experts speculate that China’s military intelligence apparatus may be pushing boundaries to assert global dominance. One of their common tactics involves sending spear-phishing emails to employees working in critical infrastructure sectors, tricking them into revealing sensitive access credentials or installing malware for long-term surveillance.

As geopolitical alliances grow increasingly fragile, these covert digital operations highlight the rising threat of state-sponsored cyber espionage — not just against traditional adversaries, but even among supposed allies.

 

Join our LinkedIn group Information Security Community!

Naveen Goud
Naveen Goud is a writer at Cybersecurity Insiders covering topics such as Mergers & Acquisitions, Startups, Cyber Attacks, Cloud Security and Mobile Security

No posts to display