Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Hafnium

Also known as: Operation Exchange Marauder, ATK233, G0125, Red Dev 13, Silk Typhoon, MURKY PANDA, tracked as, malicious actors, APT groups, hackers, APT 31, Judgment Panda, Zirconium, Leviathan, APT 40, TEMP.Periscope by cybersecurity experts, DearCry, Germany, Indonesia, elsewhere, TEMP.Periscope, TEMP.Jumper, BRONZE MOHAWK, GADOLINIUM, KRYPTONITE PANDA, G0065, ATK29, TA423, Red Ladon, ITG09, MUDCARP, ISLANDDREAMS, Gingham Typhoon, BRONZE VINEWOOD, Red keres, Violet Typhoon, TA412, ISLAND CASTLE, TIDE CASTLE

Description

HAFNIUM is attributed to China and exploited Microsoft Exchange Server vulnerabilities to gain persistent access to US organizations.

Goals & Targeting

Targeted Sectors

Defense
Education
Legal services
Non profit
Think tank
Government
Critical infrastructure
Healthcare
Energy
Utilities

Targeted Countries / Regions

CN
US
GB
IR
KP
TR
DE

AI Analysis

· 1 week ago

Executive Summary

Hafnium is a Chinese state-sponsored advanced persistent threat (APT) group known for exploiting Microsoft Exchange Server vulnerabilities to compromise US organizations. They are highly sophisticated, leveraging nation-state level capabilities to achieve their objectives primarily driven by ideological motivations.

Goals & Targeting

Hafnium's strategic objectives appear to align with broader Chinese state interests, focusing on intelligence collection and undermining US critical infrastructure. Their targeting profile specifically includes sectors that are politically sensitive or of high economic importance to the United States, leveraging their expert-level capabilities to compromise these entities through sophisticated cyberattacks.

Enhanced Description

HAFNIUM, also referred to as Operation Exchange Marauder and other aliases, is a state-sponsored threat actor attributed to China. The group gained notoriety for exploiting critical vulnerabilities in Microsoft Exchange Server products, which allowed them to deploy web shells and establish persistent access within targeted environments. Hafnium's activities primarily focus on compromising US critical infrastructure entities, including government agencies, defense contractors, and other high-value targets. Their operations demonstrate a high level of technical proficiency, leveraging custom tools such as ASPXSpy and China Chopper, and employing advanced tactics to maintain stealth and persistence.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Exploitation of Microsoft Exchange Server vulnerabilities
  • Deployment of web shells for persistence
  • Use of custom tools like ASPXSpy and China Chopper
  • Spear-phishing campaigns
  • Lateral movement within networks
  • Data exfiltration via cloud storage

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Credential Access
Discovery
Lateral Movement
Exfiltration
Collection

ATT&CK Techniques

T1560.001: Archive via Utility
T1132.001: Standard Encoding
T1213.002: Sharepoint
T1590.005: IP Addresses
T1016.001: Internet Connection Discovery
T1119: Automated Collection
T1583.005: Botnet
T1005: Data from Local System
T1110.003: Password Spraying
T1685.005: Clear Windows Event Logs
T1136.002: Domain Account
T1584.005: Botnet
T1083: File and Directory Discovery
T1567.002: Exfiltration to Cloud Storage
T1078.003: Local Accounts
T1059.003: Windows Command Shell
T1071.001: Web Protocols
T1564.001: Hidden Files and Directories
T1003.003: NTDS
T1078.004: Cloud Accounts

Software / Tooling

ASPxSpy
China Chopper
Tarrask

Campaigns & Victims

Hafnium is known for the Operation Exchange Marauder campaign, which exploited unpatched vulnerabilities in Microsoft Exchange Server to deploy web shells and gain unauthorized access. Their operations typically involve prolonged presence within targeted networks, using cloud storage for data exfiltration. Past campaigns have specifically targeted US government entities, defense contractors, and other critical infrastructure sectors.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Web shell deployments on vulnerable Exchange servers
  • Lateral movement within internal networks
  • Use of custom tools like ASPXSpy
  • Exfiltration via legitimate cloud services

Recommended Actions

  • Patch Microsoft Exchange Server instances immediately and monitor for new vulnerabilities.
  • Implement multi-factor authentication (MFA) on critical accounts and resources.
  • Monitor network traffic for unusual patterns, such as unexpected data transfers to external cloud storage or suspicious HTTP requests.
  • Conduct regular security audits to identify and remediate misconfigured web services.
  • Employ endpoint detection and response (EDR) solutions to detect malicious activity early.

Suggested Tags

APT
nation-state
espionage
supply-chain
critical-infrastructure

Confidence Assessment

There is high confidence in Hafnium's attribution to China, based on their operational tactics and known tools. However, specific details regarding long-term objectives and exact targeting criteria remain unclear.

ATT&CK Techniques

Collection
9 techniques
Credential Access
7 techniques
Discovery
6 techniques
Persistence
5 techniques
Reconnaissance
8 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Volexity Exchange Marauder March 2021 — Gruzweig, J. et al. (2021, March 2). Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities. Retrieved March 3, 2021.
  2. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  3. Microsoft Silk Typhoon MAR 2025 — Microsoft Threat Intelligence . (2025, March 5). Silk Typhoon targeting IT supply chain. Retrieved March 20, 2025.
  4. Microsoft HAFNIUM March 2020 — MSTIC. (2021, March 2). HAFNIUM targeting Exchange Servers with 0-day exploits. Retrieved March 3, 2021.
  5. apt.etda.or.th — Cited by web research for: APT 31
  6. www.cybereason.com — Cited by web research for: DearCry
  7. attack.mitre.org — Cited by web research for: T1059
  8. www.microsoft.com — Cited by web research for: Microsoft Teams
  9. www.malwarebytes.com — Cited by web research for: Guard
  10. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  11. attack.mitre.org — Cited by web research for: schtasks

Intel Summary

64

Techniques

45

Tools

0

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Tags

APT
nation-state
espionage
supply-chain
critical-infrastructure

Details

MITRE ID
G0125
Type
Nation-State
Sophistication
Expert
Resource Level
Government
Primary Motivation
Ideology
Country of Origin
China (CN)
Confidence
80%
First Seen
Jan 1, 2021
Added
May 19, 2026
STIX ID
intrusion-set--2688b13e-8e71-405a-9c40-0dee94bddf87
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.