Silk Typhoon
Chinese state-sponsored (MSS — Ministry of State Security) · Espionage / intelligence collection / IT supply chain access
Tactics, Techniques & Procedures (TTPs)
- IT supply chain targeting: compromise of MSPs, RMM vendors, PAM solutions, and cloud management providers with privileged downstream access
- Abuse of stolen API keys, OAuth tokens, and service account credentials to access downstream customer environments without direct exploitation
- BeyondTrust remote support tool zero-day exploitation (December 2024 — US Treasury breach)
- Microsoft Exchange Server mass exploitation (ProxyLogon/ProxyShell zero-days, 2021 — estimated 250,000+ servers globally)
- Targeting of Entra ID and Active Directory privileged accounts in managed service environments
- Post-compromise focus on email and document exfiltration; long-duration low-noise persistence
Known Targets
Analyst Notes
Previously tracked as HAFNIUM, Silk Typhoon is the Chinese MSS group responsible for the 2021 mass-exploitation of Microsoft Exchange Server (ProxyLogon/ProxyShell), which affected an estimated 250,000 internet-facing servers globally and was among the most impactful single-actor exploitation campaigns on record. By 2024–2025, the group had shifted its primary access vector from direct exploitation of target environments to IT supply chain compromise — targeting MSPs, RMM vendors, and PAM providers that hold keys-to-the-kingdom access to thousands of downstream organisations simultaneously. The December 2024 US Treasury breach via BeyondTrust was discovered only because a BeyondTrust vulnerability disclosure prompted an internal review; Silk Typhoon had maintained access for weeks undetected. MSP supply chain targeting means exposure is not contingent on direct attack — organisations that have not been targeted may already be compromised via their service providers.
Also Known As