logo

Silk Typhoon Targeting IT and Cloud Applications (Campaign)

ID: 0f13ff51-9e39-575b-91e3-377539ec75df

STIX ID: report--0f13ff51-9e39-575b-91e3-377539ec75df

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2025-03-05

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Microsoft Threat Intelligence reports that Silk Typhoon, a Chinese state-sponsored espionage group, is increasingly targeting IT supply-chain components, remote management tools, and cloud applications—exploiting zero-days (notably CVE-2025-0282) and exposed credentials to gain initial access, establish persistence (web shells, account resets), move laterally from on-premises to cloud (via AADConnect), abuse service principals and multi-tenant apps, and exfiltrate data from Exchange Online, OneDrive, and SharePoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.