In September 2023, FBI Director Christopher Wray sat before the House Select Committee on the Chinese Communist Party and described a campaign the intelligence community had named Volt Typhoon. Chinese state-sponsored hackers had got inside American critical infrastructure. Not corporate networks. Not defense contractors. Water treatment plants. Electrical grids. Telecommunications systems. The systems that keep lights on, water clean, and phones working. They were not, in the ordinary sense, stealing files. They were pre-positioning: sitting inside the systems so that, at a moment Beijing chose, they could disrupt or destroy services for millions of people.
The operators used what practitioners call living off the land. They did not plant a custom piece of malware, a program written to break in and easy to recognize. They used the legitimate administrative tools already on the networks, the same software authorized technicians use every day. That made them hard to see. In at least one case they kept access to an American electric grid for about 300 days before anyone identified them.
A decade earlier the public face of Chinese cyber operations had been Unit 61398 of the People's Liberation Army. A private firm, Mandiant, traced the work to a specific twelve-story office building on Datong Road in the Pudong district of Shanghai. The group reused infrastructure, left digital fingerprints, and hit so many targets that volume replaced precision. In May 2014 the Department of Justice indicted five named PLA officers, with photographs, ranks, and unit designations. The chapter compares it to a burglar who leaves a business card on the kitchen counter.
The arc from 2006 to 2024 falls, in the chapter's telling, into three phases. From about 2006 to 2014 the work was loud, bold, and technically mediocre. Unit 61398 was the most documented actor and not the only one. PLA cyber units went after defense contractors, technology firms, law firms, media organizations, and think tanks. Mandiant's 2013 report documented 141 victims across twenty major industries, intrusions going back to at least 2006, and infrastructure of more than 900 command-and-control servers, the machines that tell a compromised computer what to do next. Targeting was so broad, and security so poor, that attribution was, by intelligence-community standards, easy. GhostNet, found in 2009, had compromised 1,295 computers in 103 countries. About 30 percent of the targets were high-value diplomatic and government systems, including foreign ministries and embassies. It was wide and crude. It relied on spear-phishing, emails tailored to trick a specific person into opening them, and on known malware that left long forensic trails. Researchers at the Citizen Lab in Canada mapped the network with techniques the chapter says would not have challenged a competent graduate student.
The middle phase, roughly 2015 to 2020, turned on two changes. The 2014 indictments and a later Obama-Xi agreement on cyber theft of intellectual property pushed espionage away from identifiable military units and toward civilian intelligence, mainly the Ministry of State Security. The PLA's 2015 reforms, which reorganized the forces into joint theater commands and created the Strategic Support Force, put cyber, electronic warfare, and space under one roof. The ministry brought tradecraft, compartmentalization, and counterintelligence habits the PLA hacking units had lacked.
From about 2020, Volt Typhoon and Salt Typhoon ran on different principles. Where the earlier group, known as APT1, had used custom malware that could be fingerprinted, Volt Typhoon used tools already on the network. Where APT1 had been indiscriminate, Volt Typhoon focused on critical infrastructure with a clear military relevance. Where APT1 seemed indifferent to being caught, Volt Typhoon prioritized staying in place. Salt Typhoon went after telecommunications. It got into major American carriers, including AT&T, Verizon, and Lumen Technologies, and reached metadata on more than one million targets. Metadata is not the content of a call. It is who called whom, when, for how long, and from where. At scale it can map a government's communication network, pick out intelligence officers by whom they contact, and show a military mobilization as a change in calling patterns. Salt Typhoon did not need to listen to the calls. The FBI disrupted Volt Typhoon in January 2024 through court-authorized operations that removed malware from compromised routers. The disruption left the obvious question: what had been done in the months or years before anyone saw it. The chapter says the answer is unknown. Detected operations are the visible fraction.
Beijing's answer to being named changed on the same clock. In the APT1 years the response was flat denial. When Mandiant linked Unit 61398 to specific PLA people, the government called the findings fabrications, pointed at National Security Agency programs exposed by Edward Snowden, and offered no real reply to the technical evidence. By the mid-2020s the Ministry of State Security, usually one of the most closed organs of the state, was publishing its own attribution reports. In September 2024 it released attributions against Taiwan's Information, Communications, and Electronic Force Command, accusing Taiwanese military intelligence of cyber operations against mainland targets. The chapter's point is not the specific charge. It is that Beijing was now willing to play the attribution game on offense. That requires intelligence services to collect the evidence, a public-affairs arm to package it, and private cybersecurity firms to lend commercial credibility. That coordination was absent in 2013. By 2024 it was operating. Whether it is real defensive skill or a campaign to muddy the water, the chapter says, cannot be told from outside. Both readings fit the same output.
On July 27, 2021, China launched a vehicle into low Earth orbit that circled the planet and then released a hypersonic glide vehicle, a craft that maneuvers at more than five times the speed of sound, toward a target. A second test followed on August 13. The vehicle traveled about 40,000 kilometers over more than 100 minutes before it reentered. When the Financial Times reported it in October 2021, senior American intelligence officials described the test as having caught the United States by surprise. The surprise was not that China was building hypersonic weapons. The DF-17, a medium-range missile built to carry such a vehicle, had been tested nine or more times between 2014 and 2017, and its existence was public. The surprise was the architecture: a fractional orbital bombardment system, a path that goes partway around the Earth, mated to the glide vehicle. A warhead on that path could come from any direction, including over the South Pole, which makes a missile-defense system aimed north, at Russian and Chinese missile fields, the wrong way around. The vehicle missed by about 24 miles. For a nuclear strike on a hardened military target, 24 miles matters. For a strike on a city, it matters less. For a signal, the miss mattered less than the demonstration: a maneuvering delivery vehicle put into orbit, routed around the planet, and brought down near a target on the far side.
The Foreign Ministry called it a routine test of spacecraft reusability technology and dismissed weapons reports as inaccurate. The chapter calls the denial transparently false. No reusable spacecraft needs that flight profile, and a glide vehicle deployed from orbit has no civilian use. The denial still did a job. By refusing to acknowledge the test, Beijing avoided a diplomatic obligation to discuss it, kept the program's maturity unclear, and kept its line that it was not seeking an arms race. The Pentagon's Space Development Agency sped up a tracking-layer program, a constellation of satellites meant to see and follow hypersonic vehicles in flight. The DF-17 tests had been relatively public. The orbital test was not announced, and it was denied after it leaked. If the point was to show a deterrent, denial worked against that point. If the point was to build in secret until it could be fielded, the Financial Times story was the failure, not the test.
Between 2020 and 2021, commercial satellite analysts found construction at three sites in western China: about 350 new intercontinental ballistic missile silos in Gansu, Xinjiang, and Inner Mongolia, a fifteen- to twenty-fold increase in the silo-based force. State-aligned social media accounts said the pictures showed wind farms. Bot networks amplified the claim. The wind-farm story collapsed when analysts showed uniform spacing, road networks, and support buildings that looked nothing like wind installations and matched known Chinese missile-silo layouts exactly. Pentagon reports projected about 600 operational nuclear warheads by mid-2024, 1,000 by 2030, and potentially 1,500 by 2035. For decades China had kept a relatively small arsenal of about 200 to 300 warheads, consistent with a declared doctrine of minimum deterrence and no first use. The silo fields were not minimum deterrence on any ordinary definition. By late 2024, solid-fuel DF-31 missiles had been put in about 100 of the new silos. Solid fuel can sit readier than liquid fuel and can be launched with less preparation. With the hardening seen at the sites, Pentagon analysts read a move toward launch on warning: detecting an incoming strike and firing back before the warheads arrive. In November 2025 Beijing published a white paper describing its nuclear forces as kept at the minimum level required for national security, and blaming American missile defenses for the expansion. The chapter says the logic is not frivolous. If defenses mean fewer warheads would get through after a first strike, a larger arsenal is a rational answer inside deterrence theory. The scale still exceeds what a defense that can stop a few dozen missiles would justify. You do not need 1,500 warheads to stay at minimum deterrence against that. The gap between the stated reason and the buildup is where the uncertainty sits.
One reading treats the decade as a designed program. The loud early hacks, on this reading, harvested intellectual property, estimated in the hundreds of billions of dollars in trade secrets, and also taught the operators what American detection looked like. The indictments were tuition. The 2015 shift from PLA units to the state-security ministry was a choice of stealth over volume. Volt Typhoon's method, and its focus on infrastructure, look like preparation to disrupt in a conflict, most likely over Taiwan. The glide-vehicle technology was shown in the open through the DF-17, then escalated in secret. Silos cannot be hidden from commercial satellites. Whether a silo holds a missile, whether the missile holds a warhead, and whether the warhead works, the pictures cannot say.
The other reading says large organizations get better at what they repeat. Thousands of intrusions between 2006 and 2014 produced after-action lessons without a master plan. The 2015 reforms were about theater commands for a Taiwan contingency. Cyber under the Strategic Support Force was a byproduct. The ministry had always done its own cyber work. What changed was that the PLA's most visible units were pulled back after the embarrassment of the indictments. The hypersonic flight was a technology demonstration that leaked. The denial was a reflex, the same reflex as the wind-farm claim. The 24-mile miss fits a program still in development. The Financial Times disclosure, which forced American countermeasures, was not in any plan. The Rocket Force, even before the 2023 corruption purge, had reasons to grow its mission, its budget, and its standing against the navy and the air force. Building 350 silos employs construction crews and feeds procurement contracts. The purge of senior Rocket Force commanders for procurement fraud suggests the expansion was shaped by the same rot documented elsewhere.
Cyber operations are classified on both sides. The United States will not say the full extent of what Volt Typhoon reached, because that would expose sources and methods. China will not publish the org chart or the objectives. Satellite pictures can count silos. They cannot say if a missile is inside, if a warhead is on it, or if the warhead works. Signals intelligence can catch communications about nuclear command. It cannot say the real alert status, or the calculus of the people who hold launch authority. The 2021 flight revealed a capability. It did not reveal a deployment date, a concept for how the weapon would be used, or whether the leadership sees it as a signal or as a tool for fighting.
In 2006 the most prominent Chinese cyber unit worked out of a building a private firm could name, with techniques a graduate student could trace. By 2023 operators were inside American critical infrastructure with tools that looked like ordinary administration, and they stayed nearly a year. In 2014 China was testing a medium-range missile with a glide vehicle. By 2021 it had put one into orbit and brought it down on the far side of the planet. In 2020 the arsenal still matched minimum deterrence and no first use. By 2024 the infrastructure being built was for a force three to five times larger, with solid-fuel missiles in hardened silos. The Rocket Force corruption purge removed officers responsible for the nuclear program itself. The chapter's confidence in sorting design from muddle is medium-low. Wray's testimony was in September 2023. The FBI's disruption of the routers was in January 2024. The wind-farm posts had already failed against the spacing of the holes in Gansu, Xinjiang, and Inner Mongolia.
Comments
Reader notes
Comments aren't live yet. Send notes to @slop_dealer.