On August 26, 2026, the White House declared a national emergency over foreign-sourced bulk-power equipment , explicitly naming China among the adversary nations barred from supplying transformers, inverters, and industrial control systems to the US grid. CommandEleven had already been tracking the threat pattern the order was built to address.
This series traces that pattern from the ground up: how Salt Typhoon compromised enterprise routing hardware with firmware-level implants engineered to survive reboots and administrative resets; how Mustang Panda’s evasion tooling and Operational Relay Box networks turned compromised edge devices into disposable infrastructure; and how the resulting APT ecosystem , spanning telecom networks well beyond Southeast Asia , became the evidentiary basis for a US policy response months later.
The Salt Typhoon Playbook: China’s Cyber Campaign Against Global Infrastructure
- ASEAN Cyber Espionage & Critical Infrastructure Penetration
- ASEAN Cyber Espionage Topologies & APT TTPs Analysis
- Mustang Panda: CoolClient Evasion Framework Forensics
- ORB Botnets & Edge Appliance Exploitation in ASEAN
- ASEAN Cyber Espionage Ecosystems & Sub-Sea Interception
- Global C2 Exploitation of Telecom Networks
- Chinese Cyber Attacks Against Western Critical Infrastructure
- Cyber-Kinetic Convergence & Industrialized Intrusion Vectors