Skip to content
← All Threat Actors
Nation-State high China (PRC)

Silk Typhoon

Chinese state-sponsored (MSS — Ministry of State Security) · Espionage / intelligence collection / IT supply chain access

Reports 1
Active Since 2019
Last Reported 1 Jun 2026
Sectors Targeted finance, healthcare, critical-infrastructure, communications, transport

Tactics, Techniques & Procedures (TTPs)

  • IT supply chain targeting: compromise of MSPs, RMM vendors, PAM solutions, and cloud management providers with privileged downstream access
  • Abuse of stolen API keys, OAuth tokens, and service account credentials to access downstream customer environments without direct exploitation
  • BeyondTrust remote support tool zero-day exploitation (December 2024 — US Treasury breach)
  • Microsoft Exchange Server mass exploitation (ProxyLogon/ProxyShell zero-days, 2021 — estimated 250,000+ servers globally)
  • Targeting of Entra ID and Active Directory privileged accounts in managed service environments
  • Post-compromise focus on email and document exfiltration; long-duration low-noise persistence

Known Targets

US Treasury Department (BeyondTrust breach, Dec 2024 — ~3,000 unclassified files exfiltrated)IT managed service providers globallyHealthcare, legal, and defence sector organisations via MSP accessGovernment agencies with foreign policy remitCOVID-era pharmaceutical and public health research organisations

Analyst Notes

Previously tracked as HAFNIUM, Silk Typhoon is the Chinese MSS group responsible for the 2021 mass-exploitation of Microsoft Exchange Server (ProxyLogon/ProxyShell), which affected an estimated 250,000 internet-facing servers globally and was among the most impactful single-actor exploitation campaigns on record. By 2024–2025, the group had shifted its primary access vector from direct exploitation of target environments to IT supply chain compromise — targeting MSPs, RMM vendors, and PAM providers that hold keys-to-the-kingdom access to thousands of downstream organisations simultaneously. The December 2024 US Treasury breach via BeyondTrust was discovered only because a BeyondTrust vulnerability disclosure prompted an internal review; Silk Typhoon had maintained access for weeks undetected. MSP supply chain targeting means exposure is not contingent on direct attack — organisations that have not been targeted may already be compromised via their service providers.

Also Known As

HAFNIUM (Microsoft legacy designation, 2021)Dev-0401 (partial overlap)