This is the Trace Id: 3cc9a799300b0bbee4c4b11e3d63af03

Register for the May 6 SANS Cyber Solutions Fest – Cloud & Detection and Response Tracks. Register

Nation State Actor

Silk Typhoon

Blue hexagon pattern with O/O text.
The actor Microsoft tracks as Silk Typhoon (HAFNIUM) is a nation-state activity group based out of China. Silk Typhoon (HAFNIUM) is known to primarily target healthcare, law firms, higher education, defense contractors, policy think tanks, and non-governmental organization (NGOs) located in the United States, Australia, Japan, and Vietnam. Silk Typhoon (HAFNIUM) focuses on reconnaissance and data gathering by searching open websites for leaked data about the targeted infrastructure, as well using tools like China Chopper and exploiting 0-day vulnerabilities.

DETAILS

Also known as:

Country of origin:

Countries targeted:

Industries targeted:

Microsoft Threat Intelligence: Recent Silk Typhoon Articles

HAFNIUM targeting Exchange Servers with 0-day exploits

On-Premises Exchange Server Vulnerabilities Resource Center

Follow Microsoft Security