logo

China's Silk Typhoon, tied to US Treasury break-in, now hammers IT and govt targets

ID: 60bea957-dbc7-536e-b87b-47fa0c0891d7

STIX ID: report--60bea957-dbc7-536e-b87b-47fa0c0891d7

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-03-05

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Silk Typhoon (aka Hafnium) has conducted an ongoing espionage campaign since late 2024, leveraging stolen API keys, cloud credentials, and multiple zero-day exploits (including CVE-2025-0282, CVE-2023-3519, CVE-2024-3400) to compromise US Treasury systems, IT companies and state/local government agencies; Microsoft notes the group's shift toward targeting remote management tools and cloud applications, and US prosecutors have charged 12 alleged members.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.