By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: China-Linked Silk Typhoon Expands Cyber Attacks to IT Supply Chains for Initial Access
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > China-Linked Silk Typhoon Expands Cyber Attacks to IT Supply Chains for Initial Access
Tech News

China-Linked Silk Typhoon Expands Cyber Attacks to IT Supply Chains for Initial Access

By Viral Trending Content 4 Min Read
Share
SHARE

Mar 05, 2025Ravie LakshmananNetwork Security / Data Breach

Cyber Attacks to IT Supply Chains

The China-lined threat actor behind the zero-day exploitation of security flaws in Microsoft Exchange servers in January 2021 has shifted its tactics to target the information technology (IT) supply chain as a means to obtain initial access to corporate networks.

That’s according to new findings from the Microsoft Threat Intelligence team, which said the Silk Typhoon (formerly Hafnium) hacking group is now targeting IT solutions like remote management tools and cloud applications to obtain a foothold.

“After successfully compromising a victim, Silk Typhoon uses the stolen keys and credentials to infiltrate customer networks where they can then abuse a variety of deployed applications, including Microsoft services and others, to achieve their espionage objectives,” the tech giant said in a report published today.

The adversarial collective is assessed to be “well-resourced and technically efficient,” swiftly putting to use exploits for zero-day vulnerabilities in edge devices for opportunistic attacks that allow them to scale their attacks at scale and across a wide range of sectors and regions.

Cybersecurity

This includes information technology (IT) services and infrastructure, remote monitoring and management (RMM) companies, managed service providers (MSPs) and affiliates, healthcare, legal services, higher education, defense, government, non-governmental organizations (NGOs), energy, and others located in the United States and throughout the world.

Silk Typhoon has also been observed relying on various web shells to achieve command execution, persistence, and data exfiltration from victim environments. It’s also said to have demonstrated a keen understanding of cloud infrastructure, further allowing it to move laterally and harvest data of interest.

At least since late 2024, the attackers have been linked to a new set of methods, chief among which concerns the abuse of stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to conduct supply chain compromises of downstream customers.

“Leveraging access obtained via the API key, the actor performed reconnaissance and data collection on targeted devices via an admin account,” Microsoft said, adding targets of this activity mainly encompassed the state and local government, as well as the IT sector.

Some of the other initial access routes adopted by Silk Typhoon entail the zero-day exploitation of a security flaw in Ivanti Pulse Connect VPN (CVE-2025-0282) and the use of password spray attacks using enterprise credentials surfaced from leaked passwords on public repositories hosted on GitHub and others.

Also exploited by the threat actor as a zero-day are –

  • CVE-2024-3400, a command injection flaw in Palo Alto Networks firewalls
  • CVE-2023-3519, An unauthenticated remote code execution (RCE) vulnerability affecting Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway
  • CVE-2021-26855 (aka ProxyLogon), CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065, a set of vulnerabilities impacting Microsoft Exchange Server
Cybersecurity

A successful initial access is followed by the threat actor taking steps to move laterally from on-premises environments to cloud environments, and leverage OAuth applications with administrative permissions to perform email, OneDrive, and SharePoint data exfiltration via the MSGraph API.

In an attempt to obfuscate the origin of their malicious activities, Silk Typhoon relies on a “CovertNetwork” comprising compromised Cyberoam appliances, Zyxel routers, and QNAP devices, a hallmark of several Chinese state-sponsored actors.

“During recent activities and historical exploitation of these appliances, Silk Typhoon utilized a variety of web shells to maintain persistence and to allow the actors to remotely access victim environments,” Microsoft said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Gas Networks Ireland to connect Cork waste-to-energy plant to national gas grid

This Toshiba Rice Cooker Is Becoming a Quiet Favorite for Busy Families

Trinity PhD student probes new biology-based mental health model

iRobot Promo Code: 15% Off

Samsung One UI 9 Gets Screen Time Feature that Google Should’ve Made

TAGGED: Cloud security, Cyber Security, Cybersecurity, data breach, Incident response, Internet, network security, Threat Intelligence, Zero-Day
Share This Article
Facebook Twitter Copy Link
Previous Article DOGE’s $1 Federal Spending Limit Is Straight Out of the Twitter Playbook
Next Article Congressman Introduces Resolution to Censure Rep. Al Green
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Malaysia seeks €216m compensation from Norwegian firm over scrapped missile deal
World News
Crypto Hack Hits Echo As Monad’s eBTC Market Faces Fallout
Crypto
The Blood of Dawnwalker Promises A “Lot of Reactivity” to Player Choices in Quests
Gaming News
Gas Networks Ireland to connect Cork waste-to-energy plant to national gas grid
Tech News
This Toshiba Rice Cooker Is Becoming a Quiet Favorite for Busy Families
Tech News
Mourinho plotting to block Man Utd move for £278,000-a-week Real Madrid star
Sports
College students are booing commencement speakers celebrating AI, but the wave of hate hasn’t stopped them from using it to cheat on their exams
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?