news.mlab.sh
Threat intelligence
Threat actor

Hafnium

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2021-01-01 00:00:00
Motivation
Information theft and espionage
TLP
WHITE

(Microsoft) HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has previously compromised victims by exploiting vulnerabilities in internet-facing servers, and has used legitimate open-source frameworks, like Covenant, for command and control. Once they’ve gained access to a victim network, HAFNIUM typically exfiltrates data to file sharing sites like MEGA. In campaigns unrelated to these vulnerabilities, Microsoft has observed HAFNIUM interacting with victim Office 365 tenants. While they are often unsuccessful in compromising customer accounts, this reconnaissance activity helps the adversary identify more details about their targets’ environments. HAFNIUM operates primarily from leased virtual private servers (VPS) in the United States. (Recorded Future) Coalition officials pinned the attacks on groups tracked as APT 31, Judgment Panda, Zirconium and Leviathan, APT 40, TEMP.Periscope by cybersecurity experts, according to a press release from the UK National Cyber Security Centre. Supporting statements were also issued by NATO, the UK government, the European Union Council, Australia, Japan, Canada, Latvia, Lithuania, Estonia, Slovenia, Finland, and Denmark.

Also known as

G0125HAFNIUMMurky PandaOperation Exchange MarauderRed Dev 13Silk Typhoon

Tooling and malware

ASPXSpyChina ChopperTarraskCovenantImpacketPsExec

MITRE ATT&CK techniques

T1005 Data from Local SystemT1119 Automated CollectionT1530 Data from Cloud StorageT1095 Non-Application Layer ProtocolT1105 Ingress Tool TransferT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1033 System Owner/User DiscoveryT1057 Process DiscoveryT1083 File and Directory DiscoveryT1190 Exploit Public-Facing ApplicationT1199 Trusted RelationshipT1098 Account ManipulationT1068 Exploitation for Privilege EscalationT1590 Gather Victim Network Information

Coverage 3