The U.S. Department of Justice (DoJ) unsealed indictments against Xu Zewei and Zhang Yu, bringing unprecedented clarity to the organizational and technological underpinnings of the Hafnium hacking group, now commonly referred to as Silk Typhoon.
SentinelLABS research in the wake of these indictments identifies over ten patents for advanced forensics and data collection technologies registered by companies directly affiliated with these indicted individuals.
These tools ranging from encrypted endpoint acquisition and mobile forensics to network device traffic collection expose a formidable, previously unreported arsenal employed in support of China’s Ministry of State Security (MSS).

Hafnium’s Expanding Forensic and Offensive Toolkit
The legal documents and accompanying investigation reveal the operational hierarchy driving Silk Typhoon’s activities; Xu Zewei and Zhang Yu were found operating at the direction of the Shanghai State Security Bureau (SSSB) via Shanghai Powerock Network Co., Ltd and Shanghai Firetech Information Science and Technology Co., Ltd, respectively.
Notably, these two firms, previously unattributed in public intelligence, are documented as critical nodes in the MSS’s cyber contracting ecosystem.
Their patented software portfolio includes remote file recovery from Apple devices, automated network evidence collection, router forensics, and even advanced hard drive decryption all strong offensive tools that signal a blend of law enforcement and espionage capability, well beyond anything previously linked to Hafnium.

The organizational footprint behind Silk Typhoon extends across multiple entities and individuals. The research documents that at least three companies and four principal actors including those sanctioned after the late 2024 U.S. Treasury intrusion regularly collaborated and often blurred lines between criminal, commercial, and state-directed activity.
Leaked corporate records and chat logs from the firm i-Soon detail how actors like Yin Kecheng and Zhou Shuai, the latter a storied APT broker, facilitated sales and possibly subcontracted exploit development to other MSS-directed shops.
Microsoft’s internal alerts in early 2021 further underscore the complexities of this landscape, where state-linked and criminal actors rapidly industrialize newly discovered vulnerabilities, leading to mass global exploitation as seen during the ProxyLogon Exchange Server incident.
Complex Web Links Indicted Hackers
Beyond outlining technical capability, the new indictments shed light on the extent of state operational support.
Shanghai Firetech’s work was found to strictly follow SSSB directives a notable distinction from loosely affiliated, bottom-tier contract hackers like i-Soon, or even former leaders like Chengdu404.
More alarmingly, Firetech’s record of intellectual property rights filings far exceeds the group’s known public operations.
It includes offensive utilities such as “Apple computer comprehensive evidence collection software,” “network intelligentized control software for home appliances,” and “long-range household computer network control,” each of which points toward the likelihood of human-intelligence support and close-access intrusion capability.
Attribution obstacles are further exacerbated by the overlap between MSS regional offices and front companies.
Just as Wuhan XRZ operated as a front for the Hubei State Security Department, Shanghai Firetech’s relationships likely extend beyond the SSSB, but remain opaque due to the absence of public contracts or overt partnerships.
According to the report, The group’s ever-evolving campaign identifiers Switching between Hafnium and Silk Typhoon and their robust commercial footprint mean many tools and operations may be flying under the radar, attributed to distinct clusters, or even used by entirely different Chinese threat operations.
While some technologies theoretically offer defensive or law enforcement use cases, there has been no evidence of their promotion in legitimate markets.
The combination of sophisticated cyber capabilities, the close partnership with state security bureaus, and the organized patenting strategy all reinforce that Silk Typhoon’s operations represent a hybrid public-private approach to state cyberwarfare, posing a serious challenge to global cyber defense and attribution.
As the DoJ and security researchers have now revealed, the true scale of both technical and operational capacity within Silk Typhoon’s reach is only beginning to surface.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates