• News/
  • https://www.bleepingcomputer.com/news/security/silk-typhoon-hackers-now-target-it-supply-chains-to-breach-networks/

Silk Typhoon hackers now target IT supply chains to breach networks

BleepingComputer
·
Bill Toulas
·
Published Mar 5, 2025
·
Updated

Microsoft warns that Chinese cyber-espionage threat group 'Silk Typhoon' has shifted its tactics, now targeting remote management tools and cloud services in supply chain attacks that give them access to downstream customers. The tech giant has confirmed breaches across multiple industries, including government, IT services, healthcare, defense, education, NGOs, and energy. "They [Silk Typhoon] exploit unpatched applications that allow them to elevate their access in targeted organizations and conduct further malicious activities," reads Microsoft's report. "After successfully compromising a victim, Silk Typhoon uses the stolen keys and credentials to infiltrate customer networks where they can then abuse a variety of deployed applications, including Microsoft services and others, to achieve their espionage objectives." Silk Typhoon is a Chinese state-sponsored espionage group known for hacking the U.S. Office of Foreign Assets Control (OFAC) office in early December 2024 and stealing data from the Committee on Foreign Investment in the United States (CFIUS). Microsoft reports that Silk Typhoon switched tactics around that period, abusing stolen API keys and compromised credentials for IT providers, identity management, privileged access management, and RMM solutions, which are then used to access downstream customer networks and data. Microsoft says the attackers scan GitHub repositories and other public resources to locate leaked authentication keys or credentials and then...

Read full article

Affected Software

5 affected components
Ivanti Pulse Connect VPN
Palo Alto Networks GlobalProtect
Citrix NetScaler ADC
Citrix NetScaler Gateway
Microsoft Microsoft services
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main focus of the article regarding Silk Typhoon hackers?

The article highlights that Silk Typhoon hackers are now targeting IT supply chains to execute attacks on remote management tools and cloud services.

2

What security threats have been identified from Silk Typhoon's recent activities?

The article discusses the risk of cyber-espionage to downstream customers through supply chain attacks.

3

Which products are notably affected by the Silk Typhoon hackers' tactics?

Affected products include Ivanti Pulse Connect VPN, Palo Alto Networks GlobalProtect, Citrix NetScaler ADC, Citrix NetScaler Gateway, and various Microsoft services.

4

What are the new tactics employed by Silk Typhoon according to the article?

Silk Typhoon has shifted its focus to targeting remote management tools and cloud services for network breaches.

5

What implications do these new tactics have for organizations using affected software?

Organizations utilizing the affected software face heightened risks of cyber-espionage and unauthorized access to their networks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203