New research has revealed the corporate structure behind China’s notorious Silk Typhoon hacking group (also known as Hafnium), uncovering how state-sponsored cyber operations are conducted through private companies with sophisticated technological capabilities.
## Patent Trail Reveals Hacking Tools
Security firm SentinelOne discovered that Chinese companies linked to Silk Typhoon have filed over a dozen technology patents for advanced cyber weapons. These patents detail tools capable of:
– Collecting encrypted data from compromised devices
– Conducting forensic analysis on Apple products
– Remotely accessing routers and smart home devices
– Performing intrusion operations
## The Corporate Network
The investigation builds on a July 2025 U.S. Department of Justice indictment of two Chinese hackers, Xu Zewei and Zhang Yu, who orchestrated the 2021 Microsoft Exchange Server attacks using zero-day vulnerabilities known as ProxyLogon.
Court documents revealed the hackers worked for legitimate companies:
– **Shanghai Powerock Network Co. Ltd.** (employed Xu Zewei)
– **Shanghai Firetech Information Science and Technology Company** (employed Zhang Yu)
Both companies operated under direction from China’s Ministry of State Security (MSS) through the Shanghai State Security Bureau.
## Suspicious Business Activities
The timing of corporate changes raises red flags. Shanghai Powerock deregistered just one month after Microsoft publicly blamed China for the Exchange Server attacks. Zewei subsequently moved between cybersecurity firms, eventually landing at Shanghai GTA Semiconductor as an IT manager.
## Broader Implications
Dakota Cary, a China-focused strategic advisor for SentinelLabs, emphasized the significance of these findings: “This research demonstrates the strength in identifying not only the individuals behind attacks, but the companies they work for, the capabilities those companies have, and how those capabilities fortify the initiatives of the state entities.”
The investigation reveals that Shanghai Firetech’s capabilities extend far beyond what has been publicly attributed to Silk Typhoon, suggesting these tools may be shared across multiple Chinese intelligence operations or sold to other regional MSS offices.
This discovery provides unprecedented insight into China’s tiered system of offensive hacking operations, where private companies develop sophisticated cyber weapons under state direction while maintaining plausible deniability through legitimate business fronts.
