HAFNIUM is a China-linked, state-sponsored espionage threat actor best known for the large-scale exploitation of on-premises Microsoft Exchange Server vulnerabilities disclosed in March 2021, including the ProxyLogon attack chain. The group is widely associated with cyber espionage and theft of email and other sensitive enterprise data. Commonly cited aliases include Silk Typhoon, Murky Panda, Operation Exchange Marauder, and Timmy. HAFNIUM has been assessed as operating out of China and has used leased virtual private servers, including infrastructure in the United States, to support operations. The actor is strongly associated with targeting organizations in the United States, particularly defense, higher education, health care, and government-related entities, while victim reporting and follow-on investigations also show impact across Europe and other regions. The group’s most prominent tradecraft centers on exploitation of public-facing Microsoft Exchange servers for initial access, followed by deployment of web shells, mailbox access, and broader post-compromise activity. Reported HAFNIUM behaviors include use of Exchange PowerShell functionality to export mailbox data, theft of emails, downloading additional malware and offensive tooling, hiding files on compromised hosts, and use of encoded or obfuscated command-and-control traffic, including ASCII encoding. Tooling associated with HAFNIUM operations includes open-source and dual-use frameworks and utilities such as Covenant, Nishang, PowerCat, PsExec, Procdump, China Chopper, and other post-exploitation components. Post-exploitation activity attributed to HAFNIUM includes credential theft through LSASS dumping, theft of Active Directory data, lateral movement within victim networks, persistence through web shells, and data staging and compression prior to exfiltration. Reporting on the Exchange intrusions also links the actor to reconnaissance against vulnerable servers, remote command execution, and use of cloud-based file-sharing services for exfiltration. Although many other actors later exploited the same Exchange vulnerabilities, HAFNIUM is consistently identified as the first known cluster publicly tied to the campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
24 malware families attributed to this actor across reporting.
19 additional families tracked in Mallory.
22 CVEs this actor has used in observed campaigns. 22 of them exploited in the wild.
The bugs leveraged in the exploit—CVE-2021-26855 and CVE-2021-27065—were uncovered and reported to Microsoft in December by researchers at DEVCORE. | The bugs leveraged in the exploit—CVE-2021-26855 and CVE-2021-27065—were uncovered and reported to Microsoft in December by researchers at DEVCORE. On New Year’s Day, the DEVCORE researchers chained the bugs together and created a workable pre-authentication remote code execution exploit they dubbed “ProxyLogon.”
On March 4, 2021, Elastic Security identified evidence that Microsoft Exchange vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) were being exploited via telemetry; with evidence of compromise as early as February 28, 2021.
On March 2, the world was introduced to four critical zero-day vulnerabilities impacting multiple versions of Microsoft Exchange Server (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065).
These rules are also effective against the chained exploitation of the subsequent CVEs: CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
They have gained initial access to victim systems by exploiting several vulnerabilities, including CVE-2023-3519 — a vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway.
17 more CVEs tied to this actor tracked in Mallory.
119 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted the 2021 mass exploitation of on-premises Microsoft Exchange servers, resulting in tens of thousands of backdoors/web shells on victim systems worldwide.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Mentioned only as one of many threat actors associated with the ATT&CK technique/detection annotation for automated collection using Windows dir piped to findstr.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.