HAFNIUM

MITRE ATT&CK: G0125 View on attack.mitre.org

Aliases: Operation Exchange Marauder, Silk Typhoon, ATK233, Red Dev 13, MURKY PANDA, HAFNIUM, timmy

First seen
2021-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
5
Last IoC activity
2026-08-01 21:42:16
Profile updated
2026-07-07 12:34:10

Targeted industries: education-and-nonprofits defense-and-aerospace professional-services healthcare-and-pharmaceutical government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us

Context

HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.

Detection coverage

  • 2 YARA rules
  • 750 Sigma rules

Malware & tools used

  • Client Configurations (attack-pattern)
  • Password Spraying (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Web Services (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Data from Local System (attack-pattern)
  • Botnet (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Sharepoint (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Botnet (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Process Discovery (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Data from Cloud Storage (attack-pattern)
  • Automated Collection (attack-pattern)
  • Gather Victim Network Information (attack-pattern)
  • Web Shell (attack-pattern)
  • Email Addresses (attack-pattern)
  • Cloud Secrets Management Stores (attack-pattern)
  • Code Repositories (attack-pattern)
  • Exfiltration to Cloud Storage (attack-pattern)
  • Remote Email Collection (attack-pattern)
  • Rundll32 (attack-pattern)
  • Local Accounts (attack-pattern)

Reports & references

  • pwc.com — Yir Cyber Threats Report Download (report)
  • Microsoft — Rwmfii (report)
  • gov.uk — Uk And Allies Hold Chinese State Responsible For A Pervasive Pattern Of Hacking (report)
  • rnz.co.nz — Government Points Finger At China Over Cyber Attacks (report)
  • foreignminister.gov.au — Australia Joins International Partners Attribution Malicious Cyber Activity China (report)
  • MITRE ATT&CK — G0125 (report)
  • Microsoft — Hafnium Targeting Exchange Servers (report)
  • volexity.com — Active Exploitation Of Microsoft Exchange Zero Day Vulnerabilities (report)
  • splunk.com — Detecting Hafnium Exchange Server Zero Day Activity In Splunk (report)
  • reddit.com — Mass Exploitation Of Onprem Exchange Servers (report)
  • blog.rapid7.com — Rapid7S Insightidr Enables Detection And Response To Microsoft Exchange 0 Day (report)
  • twitter.com — 1366862946488451088 (report)
  • Mandiant — Detection Response To Exploitation Of Microsoft Exchange Zero Day Vulnerabilities (report)
  • CISA — Aa21 062A (report)
  • discuss.elastic.co — 266289 (report)
  • github.com — Security (report)
  • github.com — Exchange Webshell Detection (report)
  • CrowdStrike — Falcon Complete Stops Microsoft Exchange Server Zero Day Exploits (report)
  • Microsoft — Microsoft Exchange Server Vulnerabilities Mitigations March 2021 (report)
  • pastebin.com — J4L3R2Rs (report)
  • huntress.com — Rapid Response Mass Exploitation Of On Prem Exchange Servers (report)
  • github.com — Exchange Iis Worker Dropping Webshell.Md (report)
  • Microsoft — Multiple Security Updates Released For Exchange Server (report)
  • nextron-systems.com — Scan For Hafnium Exploitation Evidence With Thor Lite (report)
  • thedailybeast.com — How Chinas Devastating Microsoft Hack Puts Us All At Risk (report)

External references