logo

Silk Typhoon targeting IT supply chain

ID: dc7f998c-7790-5d1f-ab85-8e1b70af516b

STIX ID: report--dc7f998c-7790-5d1f-ab85-8e1b70af516b

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2025-03-05

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence details Silk Typhoon — a well-resourced Chinese state-aligned espionage actor — describing how the group exploits zero-days and unpatched remote management, VPN, and cloud-related products, abuses stolen API keys and credentials to access downstream customer tenants, moves laterally into cloud environments (including targeting Entra/AADConnect and service principals), and exfiltrates sensitive email and SharePoint data; the report provides observed CVEs, IoCs, detection queries, and specific mitigation and hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.