Microsoft warns that Chinese cyber-espionage threat group 'Silk Typhoon' has shifted its tactics, now targeting remote management tools and cloud services in supply chain attacks that give them access to downstream customers. The tech giant has confirmed breaches across multiple industries, including government, IT services, healthcare, defense, education, NGOs, and energy. "They [Silk Typhoon] exploit unpatched applications that allow them to elevate their access in targeted organizations and conduct further malicious activities," reads Microsoft's report. "After successfully compromising a victim, Silk Typhoon uses the stolen keys and credentials to infiltrate customer networks where they can then abuse a variety of deployed applications, including Microsoft services and others, to achieve their espionage objectives." Silk Typhoon is a Chinese state-sponsored espionage group known for hacking the U.S. Office of Foreign Assets Control (OFAC) office in early December 2024 and stealing data from the Committee on Foreign Investment in the United States (CFIUS). Microsoft reports that Silk Typhoon switched tactics around that period, abusing stolen API keys and compromised credentials for IT providers, identity management, privileged access management, and RMM solutions, which are then used to access downstream customer networks and data. Microsoft says the attackers scan GitHub repositories and other public resources to locate leaked authentication keys or credentials and then...
Silk Typhoon hackers now target IT supply chains to breach networks
BleepingComputer
·Bill Toulas
·Published Mar 5, 2025
·Updated
Affected Software
5 affected components
Ivanti Pulse Connect VPN
Palo Alto Networks GlobalProtect
Citrix NetScaler ADC
Citrix NetScaler Gateway
Microsoft Microsoft services
Frequently Asked Questions
1
What is the main focus of the article regarding Silk Typhoon hackers?
The article highlights that Silk Typhoon hackers are now targeting IT supply chains to execute attacks on remote management tools and cloud services.
2
What security threats have been identified from Silk Typhoon's recent activities?
The article discusses the risk of cyber-espionage to downstream customers through supply chain attacks.
3
Which products are notably affected by the Silk Typhoon hackers' tactics?
Affected products include Ivanti Pulse Connect VPN, Palo Alto Networks GlobalProtect, Citrix NetScaler ADC, Citrix NetScaler Gateway, and various Microsoft services.
4
What are the new tactics employed by Silk Typhoon according to the article?
Silk Typhoon has shifted its focus to targeting remote management tools and cloud services for network breaches.
5
What implications do these new tactics have for organizations using affected software?
Organizations utilizing the affected software face heightened risks of cyber-espionage and unauthorized access to their networks.