HAFNIUM
[HAFNIUM](https://attack.mitre.org/groups/G0125) is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. [HAFNIUM](https://attack.mitre.org/groups/G0125) primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. [HAFNIUM](https://attack.mitre.org/groups/G0125) has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.(Citation: Microsoft HAFNIUM March 2020)(Citation: Volexity Exchange Marauder March 2021)(Citation: Microsoft Silk Typhoon MAR 2025)
Properties
- stix_id
- intrusion-set--2688b13e-8e71-405a-9c40-0dee94bddf87
- signal_observed_at
- 2026-09-11T17:54:59+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (45)
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or serv
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, enc
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this techn
Adversaries may buy, lease, or rent a network of compromised systems that can be used during targeting. A botnet is a network of compromised systems t
Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised syste
Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notification
Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notification
Adversaries may gather information about the victim's client configurations that can be used during targeting. Information about client configurations
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense
Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, an
Adversaries may search public code repositories for information about victims that can be used during targeting. Victims may store code in repositorie
Adversaries may access data from cloud storage. Many IaaS providers offer solutions for online data object storage such as Amazon S3, Azure Storage,
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to
Adversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by Active Directory Domain Services wh
Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow fo
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversar
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file s
Adversaries may gather information about the victim's networks that can be used during targeting. Information about networks may include a variety of
Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files
Adversaries may gather the victim's IP addresses that can be used during targeting. Public IP addresses may be allocated to organizations by block, or
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external ad
Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in nu
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Ev
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain
Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The l
Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials.
Software & Tools (6)
[ASPXSpy](https://attack.mitre.org/software/S0073) is a Web shell. It has been modified by [Threat Group-3390](https://attack.mitre.org/groups/G0027)
[China Chopper](https://attack.mitre.org/software/S0020) is a [Web Shell](https://attack.mitre.org/techniques/T1505/003) hosted on Web servers to prov
[Covenant](https://attack.mitre.org/software/S1155) is a multi-platform command and control framework written in .NET. While designed for penetration
[Impacket](https://attack.mitre.org/software/S0357) is an open source collection of modules written in Python for programmatically constructing and ma
[PsExec](https://attack.mitre.org/software/S0029) is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT
[Tarrask](https://attack.mitre.org/software/S1011) is malware that has been used by [HAFNIUM](https://attack.mitre.org/groups/G0125) since at least Au
Explore this actor's full graph with Ninja Signal