Threat intelligence
- Suspected origin
- China
- First seen
- 2021-01-01 00:00:00
- Motivation
- Information theft and espionage
- TLP
- WHITE
(Microsoft) HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.
HAFNIUM has previously compromised victims by exploiting vulnerabilities in internet-facing servers, and has used legitimate open-source frameworks, like Covenant, for command and control. Once they’ve gained access to a victim network, HAFNIUM typically exfiltrates data to file sharing sites like MEGA.
In campaigns unrelated to these vulnerabilities, Microsoft has observed HAFNIUM interacting with victim Office 365 tenants. While they are often unsuccessful in compromising customer accounts, this reconnaissance activity helps the adversary identify more details about their targets’ environments.
HAFNIUM operates primarily from leased virtual private servers (VPS) in the United States.
(Recorded Future) Coalition officials pinned the attacks on groups tracked as APT 31, Judgment Panda, Zirconium and Leviathan, APT 40, TEMP.Periscope by cybersecurity experts, according to a press release from the UK National Cyber Security Centre. Supporting statements were also issued by NATO, the UK government, the European Union Council, Australia, Japan, Canada, Latvia, Lithuania, Estonia, Slovenia, Finland, and Denmark.
Also known as
G0125HAFNIUMMurky PandaOperation Exchange MarauderRed Dev 13Silk Typhoon
Tooling and malware
ASPXSpyChina ChopperTarraskCovenantImpacketPsExec
MITRE ATT&CK techniques
T1005 Data from Local SystemT1119 Automated CollectionT1530 Data from Cloud StorageT1095 Non-Application Layer ProtocolT1105 Ingress Tool TransferT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1033 System Owner/User DiscoveryT1057 Process DiscoveryT1083 File and Directory DiscoveryT1190 Exploit Public-Facing ApplicationT1199 Trusted RelationshipT1098 Account ManipulationT1068 Exploitation for Privilege EscalationT1590 Gather Victim Network Information
Coverage 3
policy
The FBI, in collaboration with the DoJ, has disrupted a Chinese-linked advanced persistent threat group known as Flax Typhoon (also tracked as Ethereal Panda and RedJuliett), and seized several domains used by Integrity…

policy
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in connection with the HAFNIUM attacks against U.S. critical infra…

apt
A Chinese national, Xu Zewei, has been extradited to the United States to face charges related to his alleged involvement with the Hafnium hacking group, also known as Silk Typhoon. He is accused of attempting to steal c…