Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
China18 malware familiesExploits CVEs in the wild

hafnium

Also known asHAFNIUMMURKY PANDAOperation Exchange MarauderSilk Typhoontimmy

HAFNIUM, also referred to in the provided content as Silk Typhoon, Murky Panda, Operation Exchange Marauder, and Timmy, is a threat actor with a long history of attacks against defense contractors, policy think tanks, higher education, and infectious disease research institutions. The content explicitly describes HAFNIUM as having conducted an exceptionally prolific 2021 campaign exploiting multiple Microsoft Exchange Server zero-day vulnerabilities. The provided material also notes that an indictment linked Xu and Zhang to two firms previously unattributed in the public domain to the HAFNIUM/Silk Typhoon threat actor group. Behavior directly attributed in the content includes searching file contents on compromised hosts, hiding files on compromised hosts, collecting IP information via IPInfo, gathering user information with whoami, using open-source command-and-control frameworks including Covenant, and exfiltrating data from email, OneDrive, and SharePoint via MSGraph. The content also references HAFNIUM in ATT&CK-style annotations for exploitation for privilege escalation and PowerShell execution, but those references are annotation metadata rather than direct operational descriptions. Separately, Sophos stated its metasploit_gather_exchange post-exploitation module was intended to help simulate an attack like HAFNIUM’s against previously compromised Exchange servers for defensive testing.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics53 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595
Active Scanning
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.003
Virtual Private Server
T1584
Compromise Infrastructure
TA0001
Initial Access
4 techniques
T1078×4
Valid Accounts
T1190×19
Exploit Public-Facing Application
T1195
Supply Chain Compromise
T1566
Phishing
TA0002
Execution
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1059.003×3
Windows Command Shell
T1059.004
Unix Shell
T1203
Exploitation for Client Execution
TA0003
Persistence
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1078×4
Valid Accounts
T1505
Server Software Component
T1505.003×5
Web Shell
TA0004
Privilege Escalation
4 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1068×9
Exploitation for Privilege Escalation
T1078×4
Valid Accounts
T1134
Access Token Manipulation
TA0005
Stealth
3 techniques
T1078×4
Valid Accounts
T1134
Access Token Manipulation
T1564×2
Hide Artifacts
T1564.001
Hidden Files and Directories
TA0006
Credential Access
2 techniques
T1040×2
Network Sniffing
T1649×2
Steal or Forge Authentication Certificates
TA0007
Discovery
5 techniques
T1016
System Network Configuration Discovery
T1033×2
System Owner/User Discovery
T1040×2
Network Sniffing
T1057
Process Discovery
T1083
File and Directory Discovery
TA0008
Lateral Movement
1 technique
T1021×2
Remote Services
TA0009
Collection
6 techniques
T1005×7
Data from Local System
T1039×2
Data from Network Shared Drive
T1114×3
Email Collection
T1119
Automated Collection
T1213×6
Data from Information Repositories
T1530
Data from Cloud Storage
TA0011
Command and Control
5 techniques
T1071×2
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1090.002×2
External Proxy
T1105
Ingress Tool Transfer
T1132×2
Data Encoding
T1219
Remote Access Tools
TA0010
Exfiltration
2 techniques
T1041×2
Exfiltration Over C2 Channel
T1567
Exfiltration Over Web Service
T1567.002×2
Exfiltration to Cloud Storage
WEAPONIZED

Associated vulnerabilities

22 CVEs this actor has used in observed campaigns. 22 of them exploited in the wild.

CVE-2021-26855ProxyLogon SSRF in Microsoft Exchange ServerIn the wildEvidence7

Hafnium gained fame following the revelation of their stealthy access to U.S. Government emails through an MES vulnerability known as ProxyLogon, which came to light in March 2021. The name Hafnium became associated with the wider abuse of the ProxyLogon vulnerabilities that followed the original Hafnium activity as lesser tier threat groups flooded the zone with exploitation attempts to opportunistically deliver payloads ranging from espionage to ransomware.

CVE-2024-12356Unauthenticated RCE in BeyondTrust PRA and RSIn the wildEvidence7

The flaw is a variant of CVE-2024-12356, which was linked to the December 2024 hack of the U.S. Treasury Department by Silk Typhoon, a state-linked actor backed by China.

CVE-2021-27065ProxyLogon post-auth arbitrary file write in Microsoft Exchange ServerIn the wildEvidence6

Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-27065 - Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-26858Microsoft Exchange Server post-auth arbitrary file write (ProxyLogon)In the wildEvidence5

Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-26858 - Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-26857Microsoft Exchange Unified Messaging insecure deserialization RCEIn the wildEvidence4

Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-26857 - Microsoft Exchange Server Remote Code Execution Vulnerability

17 more CVEs tied to this actor tracked in Mallory.

IOCS

Observables

69 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping40

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal18

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs22

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables69

Domains, IPs, and hashes tied to this actor, refreshed continuously.