BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Firms Behind Silk Typhoon Hold Patents for Hacking Tools

Chinese State-Linked Firms File Patents for Advanced Cyber Tools, Exposing Broader Silk Typhoon Espionage Network

  • Chinese companies linked to the state-backed Hacking group Silk Typhoon (also known as Hafnium) have filed for more than a dozen technology patents.
  • The patents reveal tools for encrypted data collection, forensic analysis of Apple devices, and remote access to routers and smart home devices.
  • The U.S. Department of Justice indicted two individuals, Xu Zewei and Zhang Yu, in July 2025 for their roles in 2021 cyberattacks on Microsoft Exchange Server.
  • Companies like Shanghai Powerock Network Co. Ltd. and Shanghai Firetech Information Science and Technology Company, Ltd. worked closely with regional Chinese state security agencies.
  • Links among affiliates and their patents suggest a broader and more organized Chinese cyber-espionage network than previously thought.

Chinese companies associated with the state-sponsored Hacker group known as Silk Typhoon (also called Hafnium) have registered over a dozen technology patents, according to a recent report. The patents cover cyber tools for encrypted data extraction, investigation of Apple devices, and remote access to connected devices.

- Advertisement -

The security firm SentinelOne stated that these patents belong to firms connected to Silk Typhoon. A new indictment from the U.S. Department of Justice in July 2025 accuses Xu Zewei and Zhang Yu of conducting a major 2021 cyber campaign that targeted Microsoft Exchange Server vulnerabilities. The pair reportedly worked for Shanghai Powerock Network Co. Ltd. and Shanghai Firetech Information Science and Technology Company, Ltd., under the direction of the Shanghai State Security Bureau, a local branch of China’s Ministry of State Security.

“This new insight into the Hafnium-affiliated firms’ capabilities highlights an important deficiency in the threat actor attribution space: threat actor tracking typically links campaigns and clusters of activity to a named actor,” said Dakota Cary of SentinelLabs. “Our research demonstrates the strength in identifying not only the individuals behind attacks, but the companies they work for, the capabilities those companies have, and how those capabilities fortify the initiatives of the state entities who contract with these firms.”

According to court records, Xu Zewei was affiliated with Shanghai Powerock, while Zhang Yu worked for Shanghai Firetech. U.S. authorities state both worked under state direction to conduct cyber intrusions. SentinelOne and other sources found that after the Microsoft attack was publicly linked to China, Powerock closed its operations, and Zewei later worked for Chaitin Tech and subsequently moved on to Shanghai GTA Semiconductor Ltd.

Further connections show that individuals involved had relationships with other companies, including Shanghai Heiying Information Technology Company, which was linked to hacker Yin Kecheng. The report describes that these companies have an ongoing and trusted relationship with China’s state security offices. “Shanghai Firetech worked on specific tasking handed down from MSS officers,” Cary said, adding that the firms’ role in the Chinese cyber operations is organized in a “tiered” system.

- Advertisement -

Additional research revealed patents filed by Shanghai Firetech and Shanghai Siling Commerce Consulting Center, covering tools for gathering data from Apple devices, routers, and other electronics. Some evidence suggests Shanghai Firetech also works on solutions for physically accessing individuals’ devices or data.

“The variety of tools under the control of Shanghai Firetech exceeds those attributed to Hafnium and Silk Typhoon publicly,” Cary added. “The capabilities may have been sold to other regional MSS offices, and thus not attributed to Hafnium, despite being owned by the same corporate structure.” More details are available in SentinelOne’s full report and related coverage on Silk Typhoon’s covert operations.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ex-FTX engineer Nishad Singh fined $3.7 million

Former FTX head of engineering Nishad Singh settled a Commodity Futures Trading Commission (CFTC)...

Tether’s Jesse Spiro to Chair $100M Crypto Super PAC

Tether's Head of Government Affairs, Jesse Spiro, will chair the crypto-funded Fellowship PAC ahead...

CERT-UA Impersonated, New RAT Attack Hits Ukraine

The Computer Emergency Response Team of Ukraine (CERT-UA) was impersonated in a phishing campaign...

Binance Launches Oil and Gas Futures with 100x Leverage

Binance has officially launched trading for oil and natural gas futures contracts, completing its...

Franklin Templeton Buys 250 Digital to Launch Crypto Unit

Franklin Templeton is establishing a dedicated crypto unit, Franklin Crypto, through the acquisition of...

Must Read

18 Countries With No Privacy Laws According To UN (List)

Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading