H-ISAC TLP White Threat Bulletin Microsoft Releases New Report on Silk Typhoon’s Evolving TTPs

March 6, 2025

On March 5, 2025, Microsoft released a identifying the Silk Typhoon’s evolving tactics. Silk Typhoon, also known as Hafnium, is a sophisticated Chinese state-sponsored threat actor known for its extensive espionage activities. The group is known for the exploitation of zero-day vulnerabilities in edge devices, targeting a wide array of sectors globally, such as Information Technology (IT), health, education, and government. Recently, the group shifted to target IT solutions like remote management tools and cloud applications to gain initial access, causing supply chain disruptions. 

View the detailed bulletin below. 

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272