BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Firms Behind Silk Typhoon Hold Patents for Hacking Tools

Chinese State-Linked Firms File Patents for Advanced Cyber Tools, Exposing Broader Silk Typhoon Espionage Network

  • Chinese companies linked to the state-backed Hacking group Silk Typhoon (also known as Hafnium) have filed for more than a dozen technology patents.
  • The patents reveal tools for encrypted data collection, forensic analysis of Apple devices, and remote access to routers and smart home devices.
  • The U.S. Department of Justice indicted two individuals, Xu Zewei and Zhang Yu, in July 2025 for their roles in 2021 cyberattacks on Microsoft Exchange Server.
  • Companies like Shanghai Powerock Network Co. Ltd. and Shanghai Firetech Information Science and Technology Company, Ltd. worked closely with regional Chinese state security agencies.
  • Links among affiliates and their patents suggest a broader and more organized Chinese cyber-espionage network than previously thought.

Chinese companies associated with the state-sponsored Hacker group known as Silk Typhoon (also called Hafnium) have registered over a dozen technology patents, according to a recent report. The patents cover cyber tools for encrypted data extraction, investigation of Apple devices, and remote access to connected devices.

- Advertisement -

The security firm SentinelOne stated that these patents belong to firms connected to Silk Typhoon. A new indictment from the U.S. Department of Justice in July 2025 accuses Xu Zewei and Zhang Yu of conducting a major 2021 cyber campaign that targeted Microsoft Exchange Server vulnerabilities. The pair reportedly worked for Shanghai Powerock Network Co. Ltd. and Shanghai Firetech Information Science and Technology Company, Ltd., under the direction of the Shanghai State Security Bureau, a local branch of China’s Ministry of State Security.

“This new insight into the Hafnium-affiliated firms’ capabilities highlights an important deficiency in the threat actor attribution space: threat actor tracking typically links campaigns and clusters of activity to a named actor,” said Dakota Cary of SentinelLabs. “Our research demonstrates the strength in identifying not only the individuals behind attacks, but the companies they work for, the capabilities those companies have, and how those capabilities fortify the initiatives of the state entities who contract with these firms.”

According to court records, Xu Zewei was affiliated with Shanghai Powerock, while Zhang Yu worked for Shanghai Firetech. U.S. authorities state both worked under state direction to conduct cyber intrusions. SentinelOne and other sources found that after the Microsoft attack was publicly linked to China, Powerock closed its operations, and Zewei later worked for Chaitin Tech and subsequently moved on to Shanghai GTA Semiconductor Ltd.

Further connections show that individuals involved had relationships with other companies, including Shanghai Heiying Information Technology Company, which was linked to hacker Yin Kecheng. The report describes that these companies have an ongoing and trusted relationship with China’s state security offices. “Shanghai Firetech worked on specific tasking handed down from MSS officers,” Cary said, adding that the firms’ role in the Chinese cyber operations is organized in a “tiered” system.

- Advertisement -

Additional research revealed patents filed by Shanghai Firetech and Shanghai Siling Commerce Consulting Center, covering tools for gathering data from Apple devices, routers, and other electronics. Some evidence suggests Shanghai Firetech also works on solutions for physically accessing individuals’ devices or data.

“The variety of tools under the control of Shanghai Firetech exceeds those attributed to Hafnium and Silk Typhoon publicly,” Cary added. “The capabilities may have been sold to other regional MSS offices, and thus not attributed to Hafnium, despite being owned by the same corporate structure.” More details are available in SentinelOne’s full report and related coverage on Silk Typhoon’s covert operations.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Saylor: Key Act Language Critical For Digital Yield Markets

Strategy's Michael Saylor calls the CLARITY Act a catalyst for the next wave of...

Banks In “Panic Mode” Over Crypto Bill As Bitcoin Rises

The Bitcoin Price has surged past $82,000 as traders anticipate a massive $16 trillion...

Istanbul Blockchain Week 2026 Returns This June

The fifth edition of Istanbul Blockchain Week is scheduled for June 2-3, 2026 at...

Instructure Pays Extortionists After Canvas Data Breach

Instructure, the parent company of Canvas, reached a ransom agreement with the ShinyHunters cybercrime...

Nvidia Hits $5.4 Trillion Market Cap Milestone

NVIDIA stock (NASDAQ: NVDA) hit a $5.4 trillion market cap and a yearly high...

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading