NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / HAFNIUM

HAFNIUM

G0125 China MITRE ATT&CK →

Also known as: Operation Exchange Marauder · Silk Typhoon

Overview

HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190
  • Custom malware/implant development — ATT&CK: 3 attributed custom malware families

TTPs — 44 techniques across 14 tactics

Reconnaissance

Resource Development

Execution

Persistence

Privilege Escalation

Stealth

Defense Impairment

Credential Access

Lateral Movement

Command and Control

Exfiltration

Tools & malware (6)

Tarrask · ASPXSpy · Impacket · PsExec · Covenant · China Chopper

Reporting (3)