HAFNIUM
MISPUnknown
CN
Unknown
[HAFNIUM](https://attack.mitre.org/groups/G0125) is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. [HAFNIUM](https://attack.mitre.org/groups/G0125) primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. [HAFNIUM](https://attack.mitre.org/groups/G0125) has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.(Citation: Microsoft HAFNIUM March 2020)(Citation: Volexity Exchange Marauder March 2021)(Citation: Microsoft Silk Typhoon MAR 2025)
Tecniche Utilizzate (44)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1003.001 | LSASS Memory | - |
| T1003.003 | NTDS | - |
| T1005 | Data from Local System | - |
| T1016 | System Network Configuration Discovery | - |
| T1016.001 | Internet Connection Discovery | - |
| T1018 | Remote System Discovery | - |
| T1033 | System Owner/User Discovery | - |
| T1057 | Process Discovery | - |
| T1059.001 | PowerShell | - |
| T1059.003 | Windows Command Shell | - |
| T1068 | Exploitation for Privilege Escalation | - |
| T1070.001 | Clear Windows Event Logs | - |
| T1071.001 | Web Protocols | - |
| T1078.003 | Local Accounts | - |
| T1078.004 | Cloud Accounts | - |
Riferimenti (10)
- attack.mitre.org - G0125
- microsoft.com - Hafnium Targeting Exchange Servers
- volexity.com - Active Exploitation Of Microsoft Exchange Zero Day Vulnerabilities
- splunk.com - Detecting Hafnium Exchange Server Zero Day Activity In Splunk
- reddit.com - Mass Exploitation Of Onprem Exchange Servers
- blog.rapid7.com - Rapid7s Insightidr Enables Detection And Response To Microsoft Exchange 0 Day
- twitter.com - 1366862946488451088
- fireeye.com - Detection Response To Exploitation Of Microsoft Exchange Zero Day Vulnerabilities
- us-cert.cisa.gov - Aa21 062a
- discuss.elastic.co - 266289
Alias (1552)
Malware Utilizzato (6)
Metadata
| ID: | 304 |
| Created: | 13/01/2026 17:48 |
| Updated: | 20/04/2026 16:00 |