A Chinese cyber-espionage group known as Silk Typhoon has changed its methodology and attack tactics to target IT supply chains and compromise cloud data.ย Thatโs the stark warning from a newly published analysis by Microsoft Threat Intelligence.
Given this group’s history of successfully exploiting zero-day vulnerabilities in software services such as Microsoft Exchange and Citrix NetScaler, you would be advised to take note and act accordingly.ย Hereโs what you need to know.
Silk Typhoon hackers: what we know
Silk Typhoon is already well-known as a nation-state threat actor affiliated to the Chinese government. It has a penchant for targeting defence contractors, non-governmental organisations, education, law and, despicably, healthcare sectors.
In the past, it has seemingly stuck to exploiting vulnerabilities and looking for leaked data on the open web concerning the infrastructure it’s targeting. That, Microsoft Threat Intelligence now says, has changed.
The threat analysis identified a shift in tactics and says with high confidence that Silk Typhoon is โnow targeting common IT solutions like remote management tools and cloud applications to gain initial accessโ.
โThis move aligns with a broader trend where adversaries exploit trusted third-party applications and supply chains to gain access to organisations,” said Ensar Seker, Chief Security Officer at SOCRadar.
Seker warned that itโs clear the attack scope extends beyond IT service providers, which suggests espionage and intelligence gathering remain the primary objectives, rather than immediate financial gain.
Change in Silk Typhoon tactics
The Microsoft Threat Intelligence team has been tracking attacks by Silk Typhoon since late 2024. Over that time, it observed the threat actors using compromised API keys and credentials associated with privilege access management, cloud app providers, and cloud data management companies.
This, in turn, allows Silk Typhoon hackers to access downstream customer environments.
Microsoft also notes the use of password spraying attacks and leveraging leaked corporate passwords on public repositories, such as GitHub.
โIn January 2025,โ the report confirmed, โSilk Typhoon was also observed exploiting a zero-day vulnerability in the public facing Ivanti Pulse Connect VPN (CVE-2025-0282).โ This is used to gain access to the on-premises environment, where Active Directory is dumped, passwords within key vaults stolen, and privileges escalated.
“Third party as an attack vector is reminiscent of high-profile supply chain breaches like SolarWinds and MOVEit,โ said Seker. โThreat actors recognise that exploiting a single vendor can open doors to a wide range of targets, making IT supply chains one of the biggest cybersecurity weak points.”
How to defend your business from Silk Typhoon hackers
To mitigate recent Silk Typhoon’s activity, Microsoft recommended that companies inspect log activity related to Entra Connect servers for anomalous activity. Any observed activity related to use of Microsoft Graph and eDiscovery, particularly for SharePoint, should be analysed.ย
I’ll leave the final word to Jim Routh,ย Chief Trust Officer atย Saviynt. โThe identification of this threat actor, Silk Typhoon, and its tactics helps us understand the implications for enterprise protection.”
What to do about it? “The key takeaway for an enterprise is to shrink the attack surface over time by moving to passwordless authentication where it is feasible.
“The second step is to limit the storage of credentials to specific data stores that have additive controlsย in place (PAM, continuous validation).
“The third is to seek network/endpoint capabilities that identify patterns to detect token usage and exploitation.โย
More advice from Davey