Updated Silk Typhoon, the Chinese government crew believed to be behind the December US Treasury intrusions, has been abusing stolen API keys and cloud credentials in ongoing attacks targeting IT companies and state and local government agencies since late 2024, according to Microsoft Threat Intelligence. The timing of this campaign coincides with that break-in at the US Treasury Department, during which Beijing's cyberspies stole data from workstations belonging to the Office of Foreign Assets Control (OFAC), which administers economic and trade sanctions, as well as the Office of the Treasury Secretary. These intrusions were attributed to Silk Typhoon, according to a Bloomberg report citing unnamed sources, and the Chinese snoops are believed to have gained access after stealing a BeyondTrust digital key used for remote technical support. And now it appears that the group's victims extended beyond the federal government agency. "Since late 2024, Microsoft Threat Intelligence has conducted thorough research and tracked ongoing attacks performed by Silk Typhoon," Redmond said Wednesday, noting that stolen API keys and credentials are Silk Typhoon's preferred means of breaking into victims' environments. After slipping into organizations via compromised API keys, President Xi's agents snoop around and collect data on devices using an administrative account, specifically looking for information that "overlaps with China-based interests," such as US government policy, legal proc...
China's Silk Typhoon blamed for ongoing IT, govt break-ins
The Register
·Jessica Lyons
·Published Mar 5, 2025
·Updated
Affected Software
4 affected components
Ivanti Pulse Connect VPN
Citrix NetScaler ADC
Citrix NetScaler Gateways
Palo Alto Networks firewalls
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses ongoing cyberattacks attributed to China's Silk Typhoon group targeting IT companies and government agencies.
2
What security implications are discussed in the article?
The article highlights the risks posed by the abuse of stolen API keys and cloud credentials in ongoing cyber operations.
3
Which threat actor is identified in the article?
The threat actor identified is China's Silk Typhoon, suspected of being behind various cyber intrusions.
4
What products or software are mentioned as affected in the article?
Affected products include Ivanti Pulse Connect VPN, Citrix NetScaler ADC, Citrix NetScaler Gateways, and Palo Alto Networks firewalls.
5
What type of organizations are being targeted by Silk Typhoon?
Silk Typhoon is targeting IT companies as well as state and local government agencies.