Initial Access
2 techniques·derived
Exchange, Ivanti, Palo Alto, and Citrix appliances. Compromise of IT providers and PAM vendors to reach downstream customers.
Ran the ProxyLogon mass exploitation that web-shelled tens of thousands of Exchange servers, then pivoted to attacking the IT supply chain.
Silk Typhoon — reported as HAFNIUM during its most notorious campaign — conducted one of the most consequential mass exploitation events in enterprise history.
In early 2021 the group exploited four Exchange Server zero-days, chained as ProxyLogon, to reach unauthenticated remote code execution on internet-facing mail servers. What made the campaign extraordinary was its final phase: in the days immediately before Microsoft's out-of-band patch, the actor shifted from targeted exploitation to indiscriminate mass scanning, dropping web shells on every reachable vulnerable server it could find. Tens of thousands of organisations were compromised in a matter of days — small businesses, local governments, and schools that had never plausibly been intelligence targets. The FBI subsequently obtained court authorisation to remotely delete web shells from hundreds of U.S. servers whose owners had not responded to notification.
Since 2024 the group has shifted strategy toward the IT supply chain. Rather than attacking targets directly, it compromises the IT service providers, identity management vendors, remote monitoring platforms, and privileged access management products those targets depend on — then uses stolen API keys and service credentials to move downstream into many customer tenants at once. Its December 2024 compromise of BeyondTrust led to access at the U.S. Department of the Treasury.
In July 2025 the U.S. Department of Justice unsealed charges against two Chinese nationals, identifying Shanghai Powerock Network Co. as a contractor operating at the direction of the Shanghai State Security Bureau.
Down to the named unit where public evidence supports it.
The U.S. Department of Justice charged Xu Zewei and Zhang Yu in July 2025, alleging Xu acted at the direction of the Shanghai State Security Bureau while employed by Shanghai Powerock Network Co. Ltd. The indictment covers both the 2021 Exchange campaign and 2020 intrusions targeting COVID-19 vaccine research at U.S. universities. Xu was arrested in Italy in July 2025.
Attributing sources
7 designators across 6 organisations.
3 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Custom loader chain observed in later supply-chain intrusions.
Shared, commodity & living-off-the-land
Minimal ASPX web shell — the payload dropped en masse during the ProxyLogon campaign.
Open-source .NET C2 framework used for post-exploitation.
PowerShell offensive framework used for reverse shells and privilege escalation.
PowerShell netcat implementation for tunnelling and reverse shells.
Cloud and PAM API keys harvested from providers, used to authenticate legitimately into downstream customer tenants.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by Silk Typhoon | ||
|---|---|---|---|---|
| CVE-2025-02820-dayKEVransomware | 9.0 | Ivanti Connect SecureIvanti | 1 Dec 2024 | Ivanti Connect Secure stack overflow exploited as a zero-day against enterprise VPN appliances.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2024-3400KEVransomware | 10.0 | PAN-OS GlobalProtectPalo Alto Networks | 1 Apr 2024 | PAN-OS GlobalProtect command injection exploited for root access to firewalls at targeted organisations.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2023-3519KEVransomware | 9.8 | Citrix NetScalerCitrix | 1 Aug 2023 | Citrix NetScaler unauthenticated RCE used for perimeter access to targeted networks.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2021-34473KEVransomware | 9.8 | Microsoft Exchange ServerMicrosoft | 1 Aug 2021 | ProxyShell chain exploited after disclosure for continued Exchange access where ProxyLogon had been patched.SRCCISA ↗ |
| CVE-2021-268550-dayKEVransomware | 9.8 | Microsoft Exchange ServerMicrosoft | 3 Jan 2021 | ProxyLogon SSRF, the entry point of the four-bug Exchange chain. Exploited from early January 2021, escalating to indiscriminate mass web-shelling in the days before Microsoft's out-of-band patch.SRCVolexity ↗ |
| CVE-2021-270650-dayKEVransomware | 7.8 | Microsoft Exchange ServerMicrosoft | 3 Jan 2021 | Post-authentication arbitrary file write, completing the ProxyLogon chain to write a web shell to an IIS-accessible path.SRCMicrosoft Threat Intelligence ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
2 techniques·derived
Exchange, Ivanti, Palo Alto, and Citrix appliances. Compromise of IT providers and PAM vendors to reach downstream customers.
3 techniques·derived
China Chopper deployed at scale during ProxyLogon. Service principal credential addition in Entra ID.
1 technique·derived
Stolen API keys used to authenticate into customer cloud tenants.
2 techniques·derived
Bulk mailbox export from compromised Exchange servers.
1 technique·derived
MEGA and similar services used for staging stolen data.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Exchange, Ivanti, Palo Alto, and Citrix appliances
Compromise of IT providers and PAM vendors to reach downstream customers
China Chopper deployed at scale during ProxyLogon
Service principal credential addition in Entra ID
Stolen API keys used to authenticate into customer cloud tenants
Bulk mailbox export from compromised Exchange servers
MEGA and similar services used for staging stolen data
Four Exchange zero-days chained for unauthenticated RCE. In the days before Microsoft's out-of-band patch the actor shifted from targeted exploitation to indiscriminate mass web-shelling, compromising tens of thousands of organisations. The FBI later obtained court authorisation to remotely remove web shells from U.S. servers.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Both MSS-linked, both exploiting trusted upstream providers to reach many downstream victims at once.
Both operate through the PRC contractor ecosystem; both adopted ProxyLogon within days of each other in March 2021.
Both MSS provincial-bureau contractor operations with named front companies.
Curated links to the reports that established what is known about this group.