Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Before the celebrity gossip raged, Rainie Louie observed the scene at her family’s small-town restaurant.

Hailey Bieber debuts Skims campaign with Everyday Cotton

Reese Witherspoon sports Chanel on ‘Elle’ promotional tour

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » China-linked silk typhoons expand cyberattacks and supply chains for first access
Celebrities

China-linked silk typhoons expand cyberattacks and supply chains for first access

By March 5, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 5, 2025Ravi LakshmananNetwork Security/Data Breaches

Cyber ​​attacks against it supply chains

In January 2021, China-lined threat actors behind the zero-day exploitation of security flaws in Microsoft Exchange servers shifted their tactics to target information technology (IT) supply chains as a way to gain early access to corporate networks.

This is based on new research from the Microsoft Threat Intelligence team, Silk Timbin (formerly Hafnium) hacking groups are currently targeting solutions such as remote management tools and cloud applications to gain footing.

“After successfully breaching the victim, Silk Tieun can use stolen keys and credentials to infiltrate customer networks and exploit various deployed applications, including Microsoft Services, to achieve spy’s goals.”

Adversary groups are rated as “resource-rich and technically efficient” and quickly use exploits to use zero-day vulnerabilities on edge devices to allow attacks to be expanded across large and wide sectors and regions.

Cybersecurity

These include information technology (IT) services and infrastructure, remote monitoring and management (RMM) companies, managed service providers (MSPs) and affiliates, healthcare, legal services, higher education, defense, government, non-governmental, non-governmental organizations (NGOs), energy, and others located in the United States and around the world.

Silk type osse has been observed relying on various web shells to achieve command execution, persistence, and data removal from the victim environment. It is also said to have demonstrated a keen understanding of cloud infrastructure, allowing it to move laterally and harvest data of interest.

At least since late 2024, attackers have been linked to a new set of methods, including the abuse of stolen API keys and qualifications related to privileged access management (PAM), cloud app providers and cloud data management companies, which involve implementing supply chain compromises for downstream customers.

“Using access obtained through API keys, actors performed reconnaissance and data collection on target devices through their management accounts,” Microsoft said, adding targets for this activity, covering primarily the state and local governments and the IT sector.

Some of the other early access routes adopted by Silk Typhoon involve the use of zero-day security flaws in the Ivanti Pulse Connect VPN (CVE-2025-0282) and password spray attacks using enterprise credentials that have emerged from leaked passwords in public repositories such as Github.

Also, what was misused by a threat actor as Zero Day –

CVE-2024-3400, Palo Alto Network Firewall command injection flaw CVE-2023-3519, CVE-2023-3519, CITRIX NETSCALER Application Delivery Control (ADC) and NetScaler Gateway CVE-2021-26855 (AKA Proxylogon) Uncertified Remote Code Executability (RCE) Vulnerabilities CVE-2021-26858, and CVE-2021-27065, a set of vulnerabilities affecting Microsoft Exchange Server

Cybersecurity

Following successful initial access, we take steps to allow threat actors to move horizontally from on-premises environments to cloud environments and leverage OAUTH applications with administrative privileges to perform email, OneDrive, and SharePoint data removal via the MSGRAPH API.

To obfuscate the origins of their malicious activities, Silk Typhoon relies on a “cover network” that includes compromised cyberoum appliances, Zyxel routers and QNAP devices, which are characteristic of actors sponsored by several Chinese countries.

“During recent activities and the historical exploitation of these appliances, the Silk Typhoon has utilized various web shells to maintain tenacity and allow actors to remotely access the victim environment,” Microsoft said.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleUS suspends sharing intelligence news with Ukraine | News of the Russian-Ukraine War
Next Article UK-based Safety Technology Startup Notice raises £1.5 million to improve workplace safety with AI

Related Posts

Hailey Bieber debuts Skims campaign with Everyday Cotton

June 22, 2026

Reese Witherspoon sports Chanel on ‘Elle’ promotional tour

June 22, 2026

Jennifer Coolidge puts a modern twist on fluffy beehives

June 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Before the celebrity gossip raged, Rainie Louie observed the scene at her family’s small-town restaurant.

Hailey Bieber debuts Skims campaign with Everyday Cotton

Reese Witherspoon sports Chanel on ‘Elle’ promotional tour

Olivia Rodrigo’s All Women’s Festival Lineup: Chapel Lawn, Kate Eye

Trending Posts

Hailey Bieber debuts Skims campaign with Everyday Cotton

June 22, 2026

Reese Witherspoon sports Chanel on ‘Elle’ promotional tour

June 22, 2026

Olivia Rodrigo’s All Women’s Festival Lineup: Chapel Lawn, Kate Eye

June 22, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.