Skip to content
ChinaState-SponsoredActive

Silk Typhoon

Ran the ProxyLogon mass exploitation that web-shelled tens of thousands of Exchange servers, then pivoted to attacking the IT supply chain.

Download profile JSON
Active
2020–present
Motivation
Espionage, IP Theft
Aliases
7
Exploited CVEs
6
ATT&CK techniques
9
Cited sources
13

Overview

Silk Typhoon — reported as HAFNIUM during its most notorious campaign — conducted one of the most consequential mass exploitation events in enterprise history.

In early 2021 the group exploited four Exchange Server zero-days, chained as ProxyLogon, to reach unauthenticated remote code execution on internet-facing mail servers. What made the campaign extraordinary was its final phase: in the days immediately before Microsoft's out-of-band patch, the actor shifted from targeted exploitation to indiscriminate mass scanning, dropping web shells on every reachable vulnerable server it could find. Tens of thousands of organisations were compromised in a matter of days — small businesses, local governments, and schools that had never plausibly been intelligence targets. The FBI subsequently obtained court authorisation to remotely delete web shells from hundreds of U.S. servers whose owners had not responded to notification.

Since 2024 the group has shifted strategy toward the IT supply chain. Rather than attacking targets directly, it compromises the IT service providers, identity management vendors, remote monitoring platforms, and privileged access management products those targets depend on — then uses stolen API keys and service credentials to move downstream into many customer tenants at once. Its December 2024 compromise of BeyondTrust led to access at the U.S. Department of the Treasury.

In July 2025 the U.S. Department of Justice unsealed charges against two Chinese nationals, identifying Shanghai Powerock Network Co. as a contractor operating at the direction of the Shanghai State Security Bureau.

Attribution

Down to the named unit where public evidence supports it.

ChinaMinistry of State Security (MSS) — Shanghai State Security Bureau, via contractorsConfirmed

The U.S. Department of Justice charged Xu Zewei and Zhang Yu in July 2025, alleging Xu acted at the direction of the Shanghai State Security Bureau while employed by Shanghai Powerock Network Co. Ltd. The indictment covers both the 2021 Exchange campaign and 2020 intrusions targeting COVID-19 vaccine research at U.S. universities. Xu was arrested in Italy in July 2025.

Attributing sources

Cross-vendor naming crosswalk

7 designators across 6 organisations.

3 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

Microsoft Threat Intelligence

index ↗
  • Silk TyphoonFormerly HAFNIUM
  • HAFNIUMRetired designator; still the dominant name for the 2021 Exchange campaign

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • MURKY PANDA

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • UNC5221partialOverlapping edge-device exploitation cluster; correlation not fully established

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • BRONZE SILHOUETTEpartialPartial overlap in reported activity

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Kaspersky GReAT

index ↗
  • Operation Exchange MarauderpartialVolexity's name for the initial 2021 exploitation, widely adopted

Descriptive names, often coined from a distinctive string or artifact in the toolset.

CISA / NSA / FBI

index ↗
  • HAFNIUM

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesUnited KingdomAustraliaJapanGermanyNetherlands

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Opera Cobalt Strike loaderloader

Custom loader chain observed in later supply-chain intrusions.

Shared, commodity & living-off-the-land

China Chopperutility

Minimal ASPX web shell — the payload dropped en masse during the ProxyLogon campaign.

Covenantframework

Open-source .NET C2 framework used for post-exploitation.

Nishangframework

PowerShell offensive framework used for reverse shells and privilege escalation.

PowerCatutility

PowerShell netcat implementation for tunnelling and reverse shells.

Stolen API keyslotl

Cloud and PAM API keys harvested from providers, used to authenticate legitimately into downstream customer tenants.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Silk Typhoon
CVE-2025-02820-dayKEVransomware9.01 Dec 2024Ivanti Connect Secure stack overflow exploited as a zero-day against enterprise VPN appliances.SRCMicrosoft Threat Intelligence
CVE-2024-3400KEVransomware10.01 Apr 2024PAN-OS GlobalProtect command injection exploited for root access to firewalls at targeted organisations.SRCMicrosoft Threat Intelligence
CVE-2023-3519KEVransomware9.81 Aug 2023Citrix NetScaler unauthenticated RCE used for perimeter access to targeted networks.SRCMicrosoft Threat Intelligence
CVE-2021-34473KEVransomware9.81 Aug 2021ProxyShell chain exploited after disclosure for continued Exchange access where ProxyLogon had been patched.SRCCISA
CVE-2021-268550-dayKEVransomware9.83 Jan 2021ProxyLogon SSRF, the entry point of the four-bug Exchange chain. Exploited from early January 2021, escalating to indiscriminate mass web-shelling in the days before Microsoft's out-of-band patch.SRCVolexity
CVE-2021-270650-dayKEVransomware7.83 Jan 2021Post-authentication arbitrary file write, completing the ProxyLogon chain to write a web shell to an IIS-accessible path.SRCMicrosoft Threat Intelligence

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

5 stages · 9 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

9 techniques across 5 tactics · 7 with actor-specific notes

Initial Access

2

Persistence

3

Lateral Movement

1

Collection

2

Exfiltration

1

Campaign timeline

  1. landmark

    ProxyLogon Mass Exchange Exploitation

    Four Exchange zero-days chained for unauthenticated RCE. In the days before Microsoft's out-of-band patch the actor shifted from targeted exploitation to indiscriminate mass web-shelling, compromising tens of thousands of organisations. The FBI later obtained court authorisation to remotely remove web shells from U.S. servers.

    CVE-2021-26855CVE-2021-27065GovernmentEducationHealthcareLegal

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.