Chinese Firms Behind Silk Typhoon Hold Patents for Hacking Tools

Chinese State-Linked Firms File Patents for Advanced Cyber Tools, Exposing Broader Silk Typhoon Espionage Network

  • Chinese companies linked to the state-backed Hacking group Silk Typhoon (also known as Hafnium) have filed for more than a dozen technology patents.
  • The patents reveal tools for encrypted data collection, forensic analysis of Apple devices, and remote access to routers and smart home devices.
  • The U.S. Department of Justice indicted two individuals, Xu Zewei and Zhang Yu, in July 2025 for their roles in 2021 cyberattacks on Microsoft Exchange Server.
  • Companies like Shanghai Powerock Network Co. Ltd. and Shanghai Firetech Information Science and Technology Company, Ltd. worked closely with regional Chinese state security agencies.
  • Links among affiliates and their patents suggest a broader and more organized Chinese cyber-espionage network than previously thought.

Chinese companies associated with the state-sponsored Hacker group known as Silk Typhoon (also called Hafnium) have registered over a dozen technology patents, according to a recent report. The patents cover cyber tools for encrypted data extraction, investigation of Apple devices, and remote access to connected devices.

- Advertisement -

The security firm SentinelOne stated that these patents belong to firms connected to Silk Typhoon. A new indictment from the U.S. Department of Justice in July 2025 accuses Xu Zewei and Zhang Yu of conducting a major 2021 cyber campaign that targeted Microsoft Exchange Server vulnerabilities. The pair reportedly worked for Shanghai Powerock Network Co. Ltd. and Shanghai Firetech Information Science and Technology Company, Ltd., under the direction of the Shanghai State Security Bureau, a local branch of China’s Ministry of State Security.

“This new insight into the Hafnium-affiliated firms’ capabilities highlights an important deficiency in the threat actor attribution space: threat actor tracking typically links campaigns and clusters of activity to a named actor,” said Dakota Cary of SentinelLabs. “Our research demonstrates the strength in identifying not only the individuals behind attacks, but the companies they work for, the capabilities those companies have, and how those capabilities fortify the initiatives of the state entities who contract with these firms.”

According to court records, Xu Zewei was affiliated with Shanghai Powerock, while Zhang Yu worked for Shanghai Firetech. U.S. authorities state both worked under state direction to conduct cyber intrusions. SentinelOne and other sources found that after the Microsoft attack was publicly linked to China, Powerock closed its operations, and Zewei later worked for Chaitin Tech and subsequently moved on to Shanghai GTA Semiconductor Ltd.

Further connections show that individuals involved had relationships with other companies, including Shanghai Heiying Information Technology Company, which was linked to hacker Yin Kecheng. The report describes that these companies have an ongoing and trusted relationship with China’s state security offices. “Shanghai Firetech worked on specific tasking handed down from MSS officers,” Cary said, adding that the firms’ role in the Chinese cyber operations is organized in a “tiered” system.

- Advertisement -

Additional research revealed patents filed by Shanghai Firetech and Shanghai Siling Commerce Consulting Center, covering tools for gathering data from Apple devices, routers, and other electronics. Some evidence suggests Shanghai Firetech also works on solutions for physically accessing individuals’ devices or data.

“The variety of tools under the control of Shanghai Firetech exceeds those attributed to Hafnium and Silk Typhoon publicly,” Cary added. “The capabilities may have been sold to other regional MSS offices, and thus not attributed to Hafnium, despite being owned by the same corporate structure.” More details are available in SentinelOne’s full report and related coverage on Silk Typhoon’s covert operations.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Crypto Fear and Greed Index Plunges to March 2020 Low

The Crypto Fear and Greed Index plunged to a reading of 5, its lowest...

Russia Blocks WhatsApp, Pushing Users to State App

Russian authorities moved to fully block Meta's WhatsApp on February 12, 2026, to funnel...

META to Build $10B Indiana Data Center for US AI Push

Meta is investing $10 billion in a new U.S. data center in Indiana to...

Strategy shifts Bitcoin buy plan to focus on preferred stock

Strategy is shifting its capital strategy to fund Bitcoin purchases from common stock sales...

Apple Releases Updates for Exploited Zero-Day Flaw

Apple has released emergency security updates for all major platforms including iOS, macOS, and...

Must Read

The 10 Best Crypto Podcasts You Can’t Miss

Table of ContentsBest Cryptocurrency Podcasts To Add To Your Playing List1. The Money Movement2. The Crypto Conversation3. The Pomp Podcast4. What Bitcoin Did5. The...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!