ATT&CKReferencesMicrosoft Silk Typhoon MAR 2025

Microsoft Silk Typhoon MAR 2025

Microsoft Threat Intelligence . (2025, March 5). Silk Typhoon targeting IT supply chain. Retrieved March 20, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupHAFNIUM

HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT).

T1005
Data from Local System
GroupHAFNIUM

HAFNIUM has collected data and files from a compromised machine.

T1068
Exploitation for Privilege Escalation
GroupHAFNIUM

HAFNIUM has targeted unpatched applications to elevate access in targeted organizations.

T1078.004
Cloud Accounts
GroupHAFNIUM

HAFNIUM has abused service principals in compromised environments to enable data exfiltration.

T1098
Account Manipulation
GroupHAFNIUM

HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts.

T1110.003
Password Spraying
GroupHAFNIUM

HAFNIUM has gained initial access through password spray attacks.

T1114.002
Remote Email Collection
GroupHAFNIUM

HAFNIUM has used web shells and MSGraph to export mailbox data.

T1119
Automated Collection
GroupHAFNIUM

HAFNIUM has used MSGraph to exfiltrate data from email, OneDrive, and SharePoint.

T1136.002
Domain Account
GroupHAFNIUM

HAFNIUM has created domain accounts.

T1190
Exploit Public-Facing Application
GroupHAFNIUM

HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server.

T1199
Trusted Relationship
GroupHAFNIUM

HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments.

T1213.002
Sharepoint
GroupHAFNIUM

HAFNIUM has abused compromised credentials to exfiltrate data from SharePoint.

T1505.003
Web Shell
GroupHAFNIUM

HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy.

T1530
Data from Cloud Storage
GroupHAFNIUM

HAFNIUM has exfitrated data from OneDrive.

T1550.001
Application Access Token
GroupHAFNIUM

HAFNIUM has abused service principals with administrative permissions for data exfiltration.

T1555.006
Cloud Secrets Management Stores
GroupHAFNIUM

HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults.

T1583.005
Botnet
GroupHAFNIUM

HAFNIUM has incorporated leased devices into covert networks to obfuscate communications.

T1584.005
Botnet
GroupHAFNIUM

HAFNIUM has used compromised devices in covert networks to obfuscate communications.

T1593.003
Code Repositories
GroupHAFNIUM

HAFNIUM has discovered leaked corporate credentials on public repositories including GitHub.

T1685.005
Clear Windows Event Logs
GroupHAFNIUM

HAFNIUM has cleared actor-performed actions from logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.