China's Silk Typhoon, tied to US Treasury break-in, now hammers IT and govt targets
ID: 60bea957-dbc7-536e-b87b-47fa0c0891d7
STIX ID: report--60bea957-dbc7-536e-b87b-47fa0c0891d7
Feed Name: The Register (Security)
Threat Score
Silk Typhoon (aka Hafnium) has conducted an ongoing espionage campaign since late 2024, leveraging stolen API keys, cloud credentials, and multiple zero-day exploits (including CVE-2025-0282, CVE-2023-3519, CVE-2024-3400) to compromise US Treasury systems, IT companies and state/local government agencies; Microsoft notes the group's shift toward targeting remote management tools and cloud applications, and US prosecutors have charged 12 alleged members.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
