PRC APT/Typhoon Label Crosswalk And Advisory Refresh Source Packet
PRC cyber labels should be treated as dated source labels, not as a single normalized alias encyclopedia. The accessible official record in this pass supports a controlled crosswalk across several label families:
UNCLASSIFIED//OPEN SOURCE
Source Packet ID: WI-SOURCEPACKET-PRC-APT-TYPHOON-2026-0001
Prepared UTC: 2026-06-18T12:13:59Z
Information cutoff UTC: 2026-06-18T12:13:59Z
Source base: FBI China cyber threat overview and dated FBI cyber alerts; DOJ January 31, 2024 Volt Typhoon / KV Botnet disruption release; DOJ March 5, 2025 i-Soon / APT27 charging release; Treasury January 17, 2025 Salt Typhoon sanctions release; OFAC cyber-related sanctions source route; CISA, NSA, FBI, FCC, State Rewards for Justice, and allied cyber-center source families; existing WARLOCK-INDEX PRC cyber and critical-infrastructure defensive source packet, Salt Typhoon telecommunications defensive source note, China/PLA source tracker, cyber nation-state actor/APT tracker, official threat-source tracker, source registers, coverage map, and global actor-domain assimilation matrix.
Analytic confidence: High for the accessible FBI, DOJ, and Treasury page identities and for source-class separation. Moderate for exact CISA, NSA, FCC, and allied advisory page-level extraction because some direct advisory routes remain access-caveated or dynamic in this environment. Low for any claim that would merge private-sector aliases, vendor labels, or technical behavior into official attribution without a dated source-class note.
Purpose: Create a safe PRC APT/Typhoon label crosswalk that records which public source uses which label, what source class supports it, and how later WARLOCK-INDEX products should route PRC cyber actor language without reproducing technical tradecraft.
Boundary: Strategic defensive source organization only. This packet does not provide exploit steps, commands, indicators, vulnerability lists, malware behavior, device guidance, scanning procedures, credential methods, lawful-intercept detail, provider-specific security findings, victim lists, network diagrams, sanctions-evasion guidance, investigative direction, or operational cyber guidance.
Bottom Line
PRC cyber labels should be treated as dated source labels, not as a single normalized alias encyclopedia. The accessible official record in this pass supports a controlled crosswalk across several label families:
- FBI's China cyber overview is the source hub for PRC cyber warning chronology and dated FBI alerts.
- FBI and Treasury both support a Salt Typhoon source lane, but the FBI source route, Treasury sanctions source route, Senate oversight route, and CISA/NSA/FBI advisory route have different evidentiary roles.
- DOJ's January 31, 2024 disruption release carries Volt Typhoon as a private-sector label in a law-enforcement source event and should remain tied to that source class.
- DOJ's March 5, 2025 i-Soon charging release supports APT27 and a DOJ-listed private-sector alias lane for that case, but allegations, company links, and aliases should not be generalized beyond the source.
- FBI alert titles support additional PRC source routes, including APT40, PRC-linked router/IoT activity, BADBAZAAR and MOONSHINE, and broader Chinese state-sponsored actor warning language, without copying technical content into WARLOCK-INDEX.
The next PRC cyber work should refresh exact CISA, NSA, FBI, FCC, and allied advisory pages where access allows, but this packet is enough to stop broader products from laundering APT labels into unqualified attribution.
Source Ledger
| Source family | Publisher | Date or access state | Primary value | Limits |
|---|---|---|---|---|
| FBI China cyber threat overview | Federal Bureau of Investigation | Accessed 2026-06-18 | FBI source hub for China cyber framing and dated alert routing | Overview route; not a complete actor dossier or alias authority |
| FBI countering Chinese state-sponsored actors global espionage advisory | FBI | Published 2025-08-27; page route accessible | Source route for broad "Chinese state-sponsored actors" language and global espionage-system warning title | PDF/detail extraction still requires a separate page-level pass; no technical extraction |
| FBI People's Republic of China cyberthreat activity alert | FBI | Published 2025-06-30; page route accessible | Source route for broad PRC cyberthreat activity title and FBI alert chronology | Page route only in this pass; no detailed extraction |
| FBI Salt Typhoon telecommunications public service announcement | FBI | Published 2025-04-24; page route accessible | FBI source route for PRC-affiliated activity publicly tracked as Salt Typhoon and telecommunications source treatment | Do not extract tip mechanics, victim/provider detail, or technical guidance |
| FBI BADBAZAAR and MOONSHINE alert | FBI | Published 2025-04-09; page route accessible | Source route for spyware/civil-society warning title connected to Uyghur, Taiwanese, and Tibetan groups | Title/source metadata only until a safe page-level pass; no malware detail |
| FBI Beijing leveraging freelance hackers and information-security companies alert | FBI | Published 2025-03-05; page route accessible | FBI source route for PRC government use of freelance hackers, information-security companies, MSS/MPS framing, and i-Soon public warning | Not proof that every private-sector alias is official attribution; no technical detail |
| DOJ i-Soon / APT27 charging release | Department of Justice | Published 2025-03-05; accessible | Legal-action source for i-Soon, MPS/MSS framing, APT27, and DOJ-listed private-sector aliases in that case | Allegations and legal source event; no intrusion details or technical procedures |
| Treasury Salt Typhoon sanctions release | Treasury / OFAC | Published 2025-01-17; accessible | Sanctions source route for Salt Typhoon, Sichuan Juxinhe, Yin Kecheng, and cross-references to other PRC cyber sanctions routes | Sanctions source, not a complete incident report or technical advisory |
| FBI enhanced visibility and hardening guidance for communications infrastructure | FBI | Published 2024-12-03; page route accessible | FBI route for communications-infrastructure defensive advisory source family tied to Salt Typhoon follow-on work | No hardening steps, device guidance, or provider-specific details extracted |
| FBI PRC-linked routers and IoT botnet operations alert | FBI | Published 2024-09-18; page route accessible | Source route for PRC-linked actor language and botnet warning title | No device, indicator, router, or botnet operation detail |
| FBI APT40 advisory | FBI | Published 2024-07-08; page route accessible | Source route for APT40 and PRC MSS advisory title language | No tradecraft extraction or alias expansion without page-level controls |
| FBI PRC state-sponsored actors critical-infrastructure alert | FBI | Published 2024-02-07; page route accessible | Source route for PRC state-sponsored critical-infrastructure access warning title | No persistence, sector, or technical detail extracted |
| FBI insecure SOHO-router exploitation alert | FBI | Published 2024-01-31; page route accessible | Source route connected to malicious cyber actors exploiting insecure SOHO routers and the Volt Typhoon source family | No vulnerable-device or exploitation detail |
| DOJ Volt Typhoon / KV Botnet disruption release | Department of Justice | Published 2024-01-31; archived page accessible | Law-enforcement source event carrying Volt Typhoon as a private-sector label and PRC state-sponsored critical-infrastructure framing | Court-authorized disruption source; no botnet, victim, or remediation mechanics |
| CISA, NSA, FBI joint advisory source family | CISA, NSA, FBI, and partners | Active source route; direct pages remain page-level follow-on | Primary intended advisory family for PRC defensive advisories and co-seal agency lists | Extract only titles, dates, issuing agencies, actor labels, and high-level themes |
| OFAC cyber-related sanctions route | Office of Foreign Assets Control | Active source route | Current route for cyber-related designations and follow-on PRC cyber sanctions status | Legal/status source only; no sanctions advice or evasion discussion |
| State Rewards for Justice cyber route | Department of State / Rewards for Justice | Active source route | Reward-source route for foreign malicious cyber activity against U.S. critical infrastructure | Do not reproduce reporting mechanics or investigative guidance |
| Allied cyber-center advisory routes | UK, Canada, Australia, New Zealand, Japan, NATO/EU where captured | Active source-family route | Cross-check lane for allied PRC cyber warnings, co-seal advisories, and national threat reports | Allied labels are not interchangeable with U.S. legal, sanctions, or advisory source classes |
Label Crosswalk
| Label or source phrase | First source captured in this packet | Source class | WARLOCK-INDEX treatment | Follow-on control |
|---|---|---|---|---|
| PRC / China state-sponsored / Chinese state-sponsored actors | FBI China overview; FBI 2025 global espionage advisory route | Official advisory phrase | Country/state-actor frame; do not equate to one named APT | Refresh exact FBI and joint-advisory pages before strengthening chronology |
| Salt Typhoon | FBI April 24, 2025 PSA; Treasury January 17, 2025 sanctions release | Official advisory/legal label by source lane | Telecommunications and communications-infrastructure source lane | Cross-read Salt Typhoon note, Treasury/OFAC status, CISA/NSA/FBI advisory routes, FCC/Senate oversight |
| Volt Typhoon | DOJ January 31, 2024 disruption release | Law-enforcement event carrying a private-sector label | Critical-infrastructure/pre-positioning source lane tied to DOJ's public release | Use as DOJ-described source language unless a direct advisory independently uses the label |
| APT40 | FBI July 8, 2024 advisory title | Official advisory title and PRC MSS source route | PRC MSS advisory source lane | Page-level extraction needed before alias or behavior expansion |
| APT27 | DOJ March 5, 2025 i-Soon charging release | Legal-action label | i-Soon / contract-hacker / PRC law-enforcement and intelligence-service source lane | Preserve allegations and source class; do not generalize case details |
| Silk Typhoon and other DOJ-listed private-sector aliases for APT27 | DOJ March 5, 2025 i-Soon charging release | DOJ-listed private-sector alias lane | Alias table support only with DOJ source note | Do not treat as independent official attribution without additional source |
| Flax Typhoon | Treasury January 17, 2025 Salt Typhoon sanctions release cross-reference | Sanctions-source route | Separate PRC malicious cyber activity source route | Follow OFAC/Treasury January 2025 designation route before use |
| APT31 | Treasury January 17, 2025 Salt Typhoon sanctions release cross-reference | Sanctions-source route | Separate PRC cyber legal/sanctions source route | Follow Treasury/DOJ/FBI March 2024 routes before use |
| BADBAZAAR and MOONSHINE | FBI April 9, 2025 alert title | Official advisory title/source route | Spyware and civil-society targeting source lane | Title/source metadata only until safe page-level refresh |
| PRC-linked actors | FBI September 18, 2024 routers/IoT alert title | Official advisory phrase | Router/IoT botnet source route without technical extraction | No device, indicator, or botnet-operation extraction |
| PRC-affiliated activity | FBI April 24, 2025 Salt Typhoon PSA | FBI public phrasing | Actor-linkage phrase for Salt Typhoon source lane | Do not upgrade to service-level attribution without source text |
| Contract hackers / information-security companies | FBI March 5, 2025 alert; DOJ March 5, 2025 charging release | FBI warning and DOJ legal-action lane | PRC state-contractor ecosystem source lane | Keep company/person records tied to legal or sanctions source events |
Extraction Rules
- Extract publisher, title, date, access date, source class, issuing agencies, actor label exactly as written, and high-level sector lane.
- Treat Typhoon, APT, actor, activity, company, and private-sector aliases as source labels until a dated source packet states who used the label.
- Keep legal actions, sanctions/designations, rewards, advisories, oversight, intelligence assessments, and allied warnings in separate source classes.
- Do not copy commands, indicators, exploit chains, hashes, domains, vulnerable products, device models, malware behavior, detection signatures, configuration steps, or incident-response procedures.
- Do not construct victim, provider, facility, or private-person dossiers. Name entities only when a public DOJ, Treasury, OFAC, or court source makes the reference necessary for strategic source routing.
- Do not convert Senate, FCC, Treasury, or Rewards for Justice material into proof of technical remediation status, active access, victim count, or provider security posture.
- Preserve uncertainty when official pages use broad language such as "linked," "affiliated," "state-sponsored," "contract hacker," or "activity."
PRC Cyber Label Routing
| Routing lane | Use | Stronger claim requires | Boundary |
|---|---|---|---|
| FBI overview and alerts | Actor-label chronology, high-level warning titles, source hub | Direct page/PDF extraction with access date | No tip mechanics, technical detail, or investigation direction |
| DOJ legal actions | Public allegations, charges, disruption events, legal source status | Court records or later DOJ updates where claim-specific | No intrusion replication, private-person dossiering, or legal conclusion beyond source |
| Treasury/OFAC sanctions | Designation and sanctions-source routing | Current OFAC record and Federal Register/legal status where needed | No sanctions advice, evasion, or finance procedure |
| CISA/NSA/FBI advisories | Defensive advisory titles, agency lists, actor labels, sector themes | Page-level advisory refresh and allied cross-check | No IOCs, CVEs, commands, exploitation, or remediation playbooks |
| FCC/Senate oversight | Telecom policy and oversight source routing | FCC dockets/orders and primary provider/regulator records | No provider vulnerability maps or network-security scoring |
| State/RFJ reward route | Broad foreign malicious cyber activity source route | State/RFJ update capture and official context | No reporting-channel mechanics |
| Allied cyber centers | Co-seal advisory and national threat-report cross-checks | Country-specific page capture and source-class notes | No cross-country alias normalization without source |
Follow-On Queue
| Product | Purpose | Primary source families |
|---|---|---|
| PRC Advisory Page-Level Refresh | Capture exact CISA, NSA, FBI, and allied PRC advisory titles, dates, issuing agencies, co-seal lists, access notes, and safe high-level themes | CISA, NSA, FBI, UK NCSC, ASD/ACSC, Canada Cyber Centre, New Zealand NCSC, Japan cyber routes |
| OFAC/Treasury PRC Cyber Designation Refresh | Capture current Salt Typhoon, Flax Typhoon, APT31, and related PRC cyber designation routes as legal/status sources | Treasury, OFAC, Federal Register where needed |
| DOJ PRC Cyber Legal-Action Source Packet | Separate i-Soon/APT27, Volt Typhoon, contract-hacker, botnet-disruption, and other PRC legal-action records | DOJ NSD, FBI, court records where public |
| FCC Telecommunications Cybersecurity Source Refresh | Capture FCC and Federal Register routes for telecom cybersecurity policy and Salt Typhoon follow-on oversight | FCC, Federal Register, Senate Commerce |
| Allied PRC Cyber Cross-Check Packet | Capture allied source use of PRC labels and co-seal advisory routes without normalizing aliases prematurely | UK, Canada, Australia, New Zealand, Japan, NATO/EU cyber routes |
Information Gaps
- CISA, NSA, FCC, and some allied advisory pages still require page-level direct refresh before exact titles, agency lists, and advisory metadata are considered complete.
- FBI pages are accessible as routes in this pass, but some linked PDF content requires separate extraction controls before stronger claim-level use.
- Public sources do not prove full alias equivalence, complete actor tasking, current access, remediation status, victim counts, or classified attribution.
- Treasury cross-references to Flax Typhoon and APT31 require their own direct designation/legal-action refreshes before those labels are expanded.
- Commercial threat-intelligence labels remain outside the corpus unless a future commercial/research source-class rule admits them with explicit source treatment.
Cross References
- PRC Cyber And Critical Infrastructure Defensive Source Packet
- Salt Typhoon And Telecommunications Defensive Source Note
- China/PLA Source Collection Tracker
- Cyber Nation-State Actor And APT Source Tracker
- Official Threat Source Collection Tracker
- Official U.S. Intelligence And Law Enforcement Source Register
- Official U.S. Source Register
- Allied And Multilateral Source Register
- Coverage Map
- Global Actor-Domain Assimilation Matrix
- Global Cyber And Critical Infrastructure Strategic Baseline
Source Base
- FBI, Cyber Threat Overview: China:
https://www.fbi.gov/investigate/cyber/cyber-threat-overview-china - FBI, Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System:
https://www.fbi.gov/investigate/cyber/alerts/2025/countering-chinese-state-sponsored-actors-compromise-of-networks-worldwide-to-feed-global-espionage-system - FBI, People's Republic of China Cyberthreat Activity:
https://www.fbi.gov/investigate/cyber/alerts/2025/peoples-republic-of-china-cyber-threat-activity - FBI, FBI Seeking Tips About PRC Targeting of U.S. Telecommunications:
https://www.fbi.gov/investigate/cyber/alerts/2025/fbi-seeking-tips-about-prc-targeting-of-us-telecommunications - FBI, BADBAZAAR and MOONSHINE Spyware Targeting Uyghur, Taiwanese, and Tibetan Groups and Civil Society Actors:
https://www.fbi.gov/investigate/cyber/alerts/2025/badbazaar-and-moonshine-spyware-targeting-uyghur-taiwanese-and-tibetan-groups-and-civil-society-actors - FBI, Beijing Leveraging Freelance Hackers and Information Security Companies to Compromise Computer Networks Worldwide:
https://www.fbi.gov/investigate/cyber/alerts/2025/beijing-leveraging-freelance-hackers-and-information-security-companies-to-compromise-computer-networks-worldwide - FBI, Enhanced Visibility and Hardening Guidance for Communications Infrastructure:
https://www.fbi.gov/investigate/cyber/alerts/2024/enhanced-visibility-and-hardening-guidance-for-communications-infrastructure - FBI, People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations:
https://www.fbi.gov/investigate/cyber/alerts/2024/peoples-republic-of-china-linked-actors-compromise-routers-and-iot-devices-for-botnet-operations - FBI, APT40 Advisory: PRC MSS Tradecraft in Action:
https://www.fbi.gov/investigate/cyber/alerts/2024/apt40-advisory-prc-mss-tradecraft-in-action - FBI, PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure:
https://www.fbi.gov/investigate/cyber/alerts/2024/prc-state-sponsored-actors-compromise-and-maintain-persistent-access-to-u-s-critical-infrastructure - FBI, Malicious Cyber Actors Exploiting Insecure SOHO Routers:
https://www.fbi.gov/investigate/cyber/alerts/2024/malicious-cyber-actors-exploiting-insecure-soho-routers - U.S. Department of Justice, U.S. Government Disrupts Botnet People's Republic of China Used to Conceal Hacking of Critical Infrastructure:
https://www.justice.gov/archives/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical - U.S. Department of Justice, Justice Department Charges 12 Chinese Contract Hackers and Law Enforcement Officers in Global Computer Intrusion Campaigns:
https://www.justice.gov/opa/pr/justice-department-charges-12-chinese-contract-hackers-and-law-enforcement-officers-global - U.S. Department of the Treasury, Treasury Sanctions Company Associated with Salt Typhoon and Hacker Associated with Treasury Compromise:
https://home.treasury.gov/news/press-releases/jy2792 - OFAC, cyber-related sanctions source route:
https://ofac.treasury.gov/sanctions-programs-and-country-information/sanctions-related-to-significant-malicious-cyber-enabled-activities - CISA, cybersecurity advisories source family:
https://www.cisa.gov/news-events/cybersecurity-advisories - NSA, cybersecurity advisories and guidance source family:
https://www.nsa.gov/Press-Room/Cybersecurity-Advisories-Guidance/ - State Department Rewards for Justice, Foreign Malicious Cyber Activity Against U.S. Critical Infrastructure:
https://rewardsforjustice.net/rewards/foreign-malicious-cyber-activity-against-u-s-critical-infrastructure/