Sci fi tunnel with neon by Amy from Pixabay

Published: August 27, 2026

COMMUNICATIONS SECURITY BRIEFING

What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer

Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure underneath them: the routers, telecommunications systems, and network management platforms that carry the traffic itself. Public reporting from CISA, the NSA, the FBI, and Microsoft Threat Intelligence describes a strategy built for long-term visibility into communications flows across U.S. networks, not a single smash-and-grab. That distinction changes what defenders need to do next.

The Typhoon Threat: Infrastructure-Level Cyber Operations

Both campaigns illustrate an evolution in state-sponsored activity toward targeting communications infrastructure rather than individual systems.

Volt Typhoon

Public reporting from CISA, the NSA, the FBI, and industry researchers indicates that Volt Typhoon has targeted U.S. critical infrastructure sectors including energy, telecommunications, transportation, and water systems. Observed techniques include exploitation of internet-facing network devices, credential reuse and administrative access, living-off-the-land operational techniques, and long-term persistence within operational networks. Analysts widely assess that this activity represents pre-positioning within infrastructure networks that could enable disruption during a geopolitical crisis.

Salt Typhoon

Salt Typhoon activity has focused primarily on telecommunications infrastructure and communications providers. Public reporting indicates attackers obtained access to telecommunications infrastructure, call-record metadata, communications-related information, and access to information subject to lawful investigative processes. This campaign reflects a strategy centered on communications intelligence collection through infrastructure access, not conventional data theft from a single target.

Strategic Implications: The Transport Layer as Battlespace

These campaigns demonstrate that communications infrastructure itself has become a strategic cyber battlespace. Even when communications payloads are encrypted, adversaries positioned within network infrastructure can still observe communication endpoints, routing relationships, packet timing and burst patterns, traffic volume and frequency, and session metadata. That information allows adversaries to perform traffic analysis, which can reveal relationships between systems and organizations.

Infrastructure compromise therefore enables several strategic capabilities:

  • Network mapping Observation of communications flows can reveal dependencies between systems and organizations.
  • Operational surveillanceTraffic patterns may expose mission tempo, system activation cycles, or coordination events.
  • Target identificationAdversaries can identify mission-critical communications nodes and operational dependencies.
  • Potential disruptionAccess to routing infrastructure may enable communications degradation or manipulation during a crisis.

Traditional cybersecurity investment has focused primarily on endpoint protection, identity and access control, and application security. Typhoon-style campaigns demonstrate that adversaries increasingly target the communications transport layer itself, a layer those investments were never designed to defend.

“Encryption protects data payloads but does not protect the visibility of the communications channel itself.”

Hardened Transport: A Structural Defense

Dispersive® Stealth Networking addresses this architectural gap by modifying how communications traverse networks. Instead of transmitting communications through a single encrypted channel, Dispersive fragments communications into encrypted micro-segments, distributes those fragments across multiple independent network paths, and securely reassembles communications only within trusted environments.

Because each infrastructure node observes only a fragment of encrypted traffic, no router, telecommunications node, or backbone device can observe a complete communications session. Even when infrastructure nodes are compromised, attackers cannot reconstruct full communications flows. This changes the operational impact of infrastructure compromise and can help ensure mission continuity in already-compromised networks without needing to first detect, locate, or extract the compromise. Instead of gaining persistent visibility into communications activity, adversaries observe partial encrypted fragments that cannot easily be correlated into coherent communications sessions.

How It Deploys

Hardened transport architectures can be deployed incrementally within existing government and mission networks without requiring large-scale infrastructure changes. Dispersive operates as a transport-layer overlay that integrates with existing network infrastructure without modifying the underlying architecture, across three layers.

Endpoint layer

Mission systems, operator workstations, and automated services run lightweight Dispersive client software that segments communications before transmission.

Transport layer

Segmented communications traverse existing infrastructure, including enterprise routers, telecommunications networks, internet backbone infrastructure, and cloud service provider networks. Because fragments are distributed across multiple independent paths, infrastructure observers cannot observe complete communications sessions. Per-channel, per-session ephemeral encryption ensures that adversaries, including existing compromises, cannot read the traffic or communicate with Dispersive-protected assets.

Gateway layer

Dispersive gateways located within trusted environments, such as enterprise data centers, cloud environments, operational command networks, and cross-domain systems, securely reassemble communications fragments before delivering traffic to mission applications.

Some functions require engagement with online presences not protected within the Dispersive gateways. For these, a dedicated Dispersive web access gateway provides a controlled egress point that lets users inside a Dispersive-protected network securely access public internet resources, web applications, SaaS, and APIs, without exposing their true network identity or transport path. 

What This Means Against Typhoon Tradecraft

Our analysis of Dispersive's effectiveness against publicly reported Volt Typhoon and Salt Typhoon techniques finds the clearest impact where these campaigns do their most damage: traffic analysis and transport-layer visibility. Fragmenting communications across multiple independent paths substantially degrades an adversary's ability to correlate flows, observe complete sessions, or reconstruct metadata, even from infrastructure nodes that are actively compromised.

That impact is not uniform, and it should not be presented as though it were. Both Typhoon actors also rely heavily on identity and credential-based techniques, valid credential reuse, credential dumping, and living-off-the-land activity that blends into legitimate administrative behavior. Because Dispersive operates at the transport layer, it does not prevent credential theft, stop an adversary who has already compromised an endpoint from acting on it, or address risk tied to provider-held data and lawful intercept systems. Those require identity and access management, endpoint detection and response, and provider-level controls doing the work they are built for.

In short, hardened transport is not a replacement for those defenses. It is the layer that sits on top of them, closing a gap none of them were designed to close in the first place.

Operating Through Compromise

Modern cyber operations, exemplified by Volt Typhoon and Salt Typhoon, assume persistent access to enterprise and telecommunications infrastructure. In many operational environments, it is no longer realistic to guarantee that endpoint networks, edge devices, or portions of the communications path are free from adversary presence.

Traditional cybersecurity approaches prioritize detection, eviction, and remediation. Necessary as those steps are, they are often time-consuming and may not align with mission timelines, particularly during active operations or crisis conditions. That gap is why there is a growing requirement to operate through compromise: maintaining mission effectiveness even when adversary presence cannot be detected, located, or immediately removed.

The approach does not assume compromise can be prevented or immediately eliminated. It focuses instead on a different objective: ensuring adversaries cannot derive meaningful intelligence or operational advantage from the communications they observe. In traditional networks, an attacker who reaches a router, switch, telecom node, or internal segment can often observe full communication sessions, correlate traffic patterns, reconstruct sensitive data flows, and identify command relationships. Dispersive disrupts that model by ensuring that no single observation point, regardless of compromise, can access a complete, coherent data stream from Dispersive-protected nodes or devices.

The critical question shifts from “can we prevent access” to “can we deny adversaries the ability to exploit what they access.The result is a new operational state: compromised, but mission capable.

Protecting AI and Autonomous Mission Systems

Modern defense and intelligence environments increasingly rely on AI-enabled and autonomous systems. These systems generate continuous communications across three operational zones: users or applications interacting with AI models, AI models coordinating with one another to execute complex workflows, and AI systems interacting with tools, databases, and operational platforms. These communications patterns create structured traffic signals that can reveal operational intent on their own, independent of payload content. Dispersive protects all three zones by preventing adversaries from observing coherent communications flows between system components, a capability that will only grow more important as AI-enabled command-and-control systems, autonomous cyber defense platforms, and distributed robotics become more prevalent.

Moving at the Speed the Threat Requires

Dispersive technology is already deployed across government, defense, and commercial environments today. Where mission urgency requires accelerated protection, organizations can move directly to operational deployment without a pilot phase, with initial capability typically established within weeks rather than months. Where empirical validation is preferred, a structured pilot deployment, run over roughly six months, can measure reduction in traffic analysis visibility, evaluate resilience against infrastructure compromise, assess integration with existing security tools, validate operational performance, and confirm mission continuity even in the presence of already-compromised endpoint networks.

Dispersive does not disrupt or impair data or communications already encrypted at the source. An on-premises option, DispersiveFabric™, gives an organization exclusive control over and access to its own data, with break-and-inspect functionality available where required.

The Bottom Line

Volt Typhoon and Salt Typhoon demonstrate a fundamental shift in cyber operations toward infrastructure-centric surveillance and disruption capabilities. Encryption protects the content of communications, but it does not prevent adversaries positioned within infrastructure from analyzing communications behavior. Protecting national security and mission communications therefore requires securing not only the data payload, but the communications transport layer itself.

Hardened transport architectures such as Dispersive Stealth Networking provide a practical mechanism for closing that gap by eliminating coherent observability of communications flows, without waiting for every endpoint, credential, and provider-side risk to be fully resolved first. For mission networks whose operations depend on reliable, defensible communications, extending security to the transport layer is a critical, and increasingly urgent, step in defending against infrastructure-centric cyber campaigns.

Analytical basis: This piece draws on publicly available reporting from U.S. government agencies, allied cybersecurity authorities, and industry threat intelligence research regarding Volt Typhoon and Salt Typhoon, including the CISA/NSA/FBI joint cybersecurity advisory “People’s Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection” (May 2023), Microsoft Threat Intelligence reporting on Volt Typhoon (May 2023), FBI and CISA reporting on Salt Typhoon, and NSA cybersecurity guidance on mitigating adversary access to communications infrastructure. Where conclusions extend beyond publicly reported facts, they represent reasoned assessments based on established cyber operational practices and communications intelligence methodologies, consistent with Dispersive's internal analysis.

Hardened Transport Is the Missing Layer Defenders Need Now

If your mission depends on communications that remain defensible even when infrastructure is compromised, our team can help you validate hardened transport against your environment.

📞 Schedule a briefing with Dispersive’s architects to assess your exposure and map a deployment path. www.dispersive.io


Header image courtesy of Amy from Pixabay.

Share
Share