Silk Typhoon Targeting IT and Cloud Applications (Campaign)
ID: 0f13ff51-9e39-575b-91e3-377539ec75df
STIX ID: report--0f13ff51-9e39-575b-91e3-377539ec75df
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-03-05
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Microsoft Threat Intelligence reports that Silk Typhoon, a Chinese state-sponsored espionage group, is increasingly targeting IT supply-chain components, remote management tools, and cloud applications—exploiting zero-days (notably CVE-2025-0282) and exposed credentials to gain initial access, establish persistence (web shells, account resets), move laterally from on-premises to cloud (via AADConnect), abuse service principals and multi-tenant apps, and exfiltrate data from Exchange Online, OneDrive, and SharePoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
