Target Industry
IT services, remote monitoring and management companies, managed service providers, healthcare, legal services, higher education, defence, government, non-governmental organisations (NGOs), and energy sectors globally.
Overview
A Chinese state-sponsored cyber-espionage group, tracked by Microsoft since 2020, is shifting its focus to targeting the IT supply chain to gain initial access to corporate networks. Silk Typhoon (formerly Hafnium) is technically efficient and well-resourced, quickly exploiting vulnerabilities in edge devices.
Impact
Silk Typhoon’s activities have a significant impact, including the theft of sensitive data from various sectors such as healthcare, legal services, higher education, defence, government, and energy. By targeting IT supply chains, they can access multiple downstream customer environments, leading to widespread data breaches.
Their attacks can disrupt the operations of targeted organisations, causing financial losses and operational downtime. Additionally, their ability to exploit zero-day vulnerabilities and use stolen credentials increases overall security risks for organisations.
Exploitation
Silk Typhoon employs several sophisticated techniques to exploit its targets. The group steals API keys and credentials to gain access to networks and systems in a bid to quickly exploit newly discovered vulnerabilities in edge devices. It also uses web shells to execute commands to maintain persistence, and exfiltrate data. Additionally, it moves laterally within networks, from on-premises environments to cloud infrastructures.
It targets Active Directory to manipulate service principals and OAuth applications, and exfiltrates data from cloud services like OneDrive, SharePoint, and Exchange. Silk Typhoon uses a “CovertNetwork” of compromised devices to obfuscate their activities
According to researchers at Microsoft, the group has recently exploited zero-day vulnerability CVE-2025-0282 (CVSS score 9.0) which affected Ivanti Pulse Connect VPNs. Over the past two years it has also been known to have exploited the following critical zero-days vulnerabilities:
- CVE-2024-3400 (CVSS score 10): a command injection flaw in Palo Alto Networks firewalls
- CVE-2023-3519 (CVSS score 9.8): an unauthenticated remote code execution (RCE) vulnerability affecting Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway.
Containment, Mitigations & Remediations
To safeguard against potential attacks, organisations using the affected software are strongly encouraged to apply the latest patches to protect against potential threats.
Threat Landscape
These activities are not limited to a specific region, affecting organisations globally, highlighting the need for robust cyber security measures and vigilance against such sophisticated threats.
It also emphasises the importance of applying the recommended patches and mitigation measures to protect systems. These critical vulnerabilities highlight the challenges which users in both personal and business environments face.
Threat Groups
Silk Typhoon, otherwise known as Hafnium, is a Chinese state-sponsored cyber-espionage group based in China. Tracked by Microsoft since 2020, it is recognised for its advanced methods and substantial resources. It is indiscriminate on which sectors it targets globally and has been seen attacking IT supply chains, healthcare, legal services, higher education, defence, government, and energy organisations. Its activities involve exploiting vulnerabilities, stealing credentials, and exfiltrating sensitive data. Silk Typhoon’s ability to quickly adapt and leverage advanced cyber tactics makes it a significant threat to organisations worldwide.
TTPs
- T1021: Remote Services
- T1190: Exploit Public-Facing Application
- T1195: Supply Chain Compromise
- T1203: Exploitation for Client Execution
- T1505.003: Server Software Component: Web Shell
- T1110.003: Brute Force: Password Spraying
- T1083: File and Directory Discovery
- T1078.004: Valid Accounts: Cloud Accounts
- T1021: Remote Services
Further Information













