Target Industry

IT services, remote monitoring and management companies, managed service providers, healthcare, legal services, higher education, defence, government, non-governmental organisations (NGOs), and energy sectors globally. 

Overview

A Chinese state-sponsored cyber-espionage group, tracked by Microsoft since 2020, is shifting its focus to targeting the IT supply chain to gain initial access to corporate networks. Silk Typhoon (formerly Hafnium) is technically efficient and well-resourced, quickly exploiting vulnerabilities in edge devices. 

Impact

Silk Typhoon’s activities have a significant impact, including the theft of sensitive data from various sectors such as healthcare, legal services, higher education, defence, government, and energy. By targeting IT supply chains, they can access multiple downstream customer environments, leading to widespread data breaches. 

Their attacks can disrupt the operations of targeted organisations, causing financial losses and operational downtime. Additionally, their ability to exploit zero-day vulnerabilities and use stolen credentials increases overall security risks for organisations.  

Exploitation

Silk Typhoon employs several sophisticated techniques to exploit its targets. The group steals API keys and credentials to gain access to networks and systems in a bid to quickly exploit newly discovered vulnerabilities in edge devices. It also uses web shells to execute commands to maintain persistence, and exfiltrate data. Additionally, it moves laterally within networks, from on-premises environments to cloud infrastructures.  

It targets Active Directory to manipulate service principals and OAuth applications, and exfiltrates data from cloud services like OneDrive, SharePoint, and Exchange. Silk Typhoon uses a “CovertNetwork” of compromised devices to obfuscate their activities 

According to researchers at Microsoft, the group has recently exploited zero-day vulnerability CVE-2025-0282 (CVSS score 9.0) which affected Ivanti Pulse Connect VPNs. Over the past two years it has also been known to have exploited the following critical zero-days vulnerabilities: 

  • CVE-2024-3400 (CVSS score 10): a command injection flaw in Palo Alto Networks firewalls 
  • CVE-2023-3519 (CVSS score 9.8): an unauthenticated remote code execution (RCE) vulnerability affecting Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. 

Containment, Mitigations & Remediations

To safeguard against potential attacks, organisations using the affected software are strongly encouraged to apply the latest patches to protect against potential threats.  

Threat Landscape

These activities are not limited to a specific region, affecting organisations globally, highlighting the need for robust cyber security measures and vigilance against such sophisticated threats. 

It also emphasises the importance of applying the recommended patches and mitigation measures to protect systems. These critical vulnerabilities highlight the challenges which users in both personal and business environments face.  

Threat Groups

Silk Typhoon, otherwise known as Hafnium, is a Chinese state-sponsored cyber-espionage group based in China. Tracked by Microsoft since 2020, it is recognised for its advanced methods and substantial resources. It is indiscriminate on which sectors it targets globally and has been seen attacking IT supply chains, healthcare, legal services, higher education, defence, government, and energy organisations. Its activities involve exploiting vulnerabilities, stealing credentials, and exfiltrating sensitive data. Silk Typhoon’s ability to quickly adapt and leverage advanced cyber tactics makes it a significant threat to organisations worldwide. 

TTPs

  • T1190: Exploit Public-Facing Application 
  • T1195: Supply Chain Compromise 
  • T1203: Exploitation for Client Execution 
  • T1505.003: Server Software Component: Web Shell 
  • T1083: File and Directory Discovery 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content