Also known as: Operation Exchange Marauder, ATK233, G0125, Red Dev 13, Silk Typhoon, MURKY PANDA, tracked as, malicious actors, APT groups, hackers, APT 31, Judgment Panda, Zirconium, Leviathan, APT 40, TEMP.Periscope by cybersecurity experts, DearCry, Germany, Indonesia, elsewhere, TEMP.Periscope, TEMP.Jumper, BRONZE MOHAWK, GADOLINIUM, KRYPTONITE PANDA, G0065, ATK29, TA423, Red Ladon, ITG09, MUDCARP, ISLANDDREAMS, Gingham Typhoon, BRONZE VINEWOOD, Red keres, Violet Typhoon, TA412, ISLAND CASTLE, TIDE CASTLE
HAFNIUM is attributed to China and exploited Microsoft Exchange Server vulnerabilities to gain persistent access to US organizations.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Hafnium is a Chinese state-sponsored advanced persistent threat (APT) group known for exploiting Microsoft Exchange Server vulnerabilities to compromise US organizations. They are highly sophisticated, leveraging nation-state level capabilities to achieve their objectives primarily driven by ideological motivations.
Goals & Targeting
Hafnium's strategic objectives appear to align with broader Chinese state interests, focusing on intelligence collection and undermining US critical infrastructure. Their targeting profile specifically includes sectors that are politically sensitive or of high economic importance to the United States, leveraging their expert-level capabilities to compromise these entities through sophisticated cyberattacks.
Enhanced Description
HAFNIUM, also referred to as Operation Exchange Marauder and other aliases, is a state-sponsored threat actor attributed to China. The group gained notoriety for exploiting critical vulnerabilities in Microsoft Exchange Server products, which allowed them to deploy web shells and establish persistent access within targeted environments. Hafnium's activities primarily focus on compromising US critical infrastructure entities, including government agencies, defense contractors, and other high-value targets. Their operations demonstrate a high level of technical proficiency, leveraging custom tools such as ASPXSpy and China Chopper, and employing advanced tactics to maintain stealth and persistence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Hafnium is known for the Operation Exchange Marauder campaign, which exploited unpatched vulnerabilities in Microsoft Exchange Server to deploy web shells and gain unauthorized access. Their operations typically involve prolonged presence within targeted networks, using cloud storage for data exfiltration. Past campaigns have specifically targeted US government entities, defense contractors, and other critical infrastructure sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is high confidence in Hafnium's attribution to China, based on their operational tactics and known tools. However, specific details regarding long-term objectives and exact targeting criteria remain unclear.
No campaigns linked yet.
No observed data linked yet.
64
Techniques
45
Tools
0
Campaigns
40
IOCs
0
Observed Data
14
Tactics