hafnium
HAFNIUM, also referred to in the provided content as Silk Typhoon, Murky Panda, Operation Exchange Marauder, and Timmy, is a threat actor with a long history of attacks against defense contractors, policy think tanks, higher education, and infectious disease research institutions. The content explicitly describes HAFNIUM as having conducted an exceptionally prolific 2021 campaign exploiting multiple Microsoft Exchange Server zero-day vulnerabilities. The provided material also notes that an indictment linked Xu and Zhang to two firms previously unattributed in the public domain to the HAFNIUM/Silk Typhoon threat actor group. Behavior directly attributed in the content includes searching file contents on compromised hosts, hiding files on compromised hosts, collecting IP information via IPInfo, gathering user information with whoami, using open-source command-and-control frameworks including Covenant, and exfiltrating data from email, OneDrive, and SharePoint via MSGraph. The content also references HAFNIUM in ATT&CK-style annotations for exploitation for privilege escalation and PowerShell execution, but those references are annotation metadata rather than direct operational descriptions. Separately, Sophos stated its metasploit_gather_exchange post-exploitation module was intended to help simulate an attack like HAFNIUM’s against previously compromised Exchange servers for defensive testing.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
Associated vulnerabilities
22 CVEs this actor has used in observed campaigns. 22 of them exploited in the wild.
Hafnium gained fame following the revelation of their stealthy access to U.S. Government emails through an MES vulnerability known as ProxyLogon, which came to light in March 2021. The name Hafnium became associated with the wider abuse of the ProxyLogon vulnerabilities that followed the original Hafnium activity as lesser tier threat groups flooded the zone with exploitation attempts to opportunistically deliver payloads ranging from espionage to ransomware.
The flaw is a variant of CVE-2024-12356, which was linked to the December 2024 hack of the U.S. Treasury Department by Silk Typhoon, a state-linked actor backed by China.
Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-27065 - Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-26858 - Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-26857 - Microsoft Exchange Server Remote Code Execution Vulnerability
17 more CVEs tied to this actor tracked in Mallory.
Observables
69 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
China-linked espionage actor associated with compromise of US Treasury systems, likely to obtain regulatory and policy intelligence.
Referenced as a major APT disclosure example used to illustrate delayed disclosure and monitored access by defenders.
Sustained finance-sector targeting across reporting periods.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.