HAFNIUM

G0125

Threat group.View on attack.mitre.org

About this group

HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.

Techniques used44

Procedure examples44

TechniqueProcedure example
T1003.001
LSASS Memory

HAFNIUM has used procdump to dump the LSASS process memory.

T1003.003
NTDS

HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT).

T1005
Data from Local System

HAFNIUM has collected data and files from a compromised machine.

T1016
System Network Configuration Discovery

HAFNIUM has collected IP information via IPInfo.

T1016.001
Internet Connection Discovery

HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`.

T1018
Remote System Discovery

HAFNIUM has enumerated domain controllers using `net group "Domain computers"` and `nltest /dclist`.

T1033
System Owner/User Discovery

HAFNIUM has used `whoami` to gather user information.

T1057
Process Discovery

HAFNIUM has used `tasklist` to enumerate processes.

T1059.001
PowerShell

HAFNIUM has used the Exchange Power Shell module Set-OabVirtualDirectoryPowerShell to export mailbox data.

T1059.003
Windows Command Shell

HAFNIUM has used `cmd.exe` to execute commands on the victim's machine.

T1068
Exploitation for Privilege Escalation

HAFNIUM has targeted unpatched applications to elevate access in targeted organizations.

T1071.001
Web Protocols

HAFNIUM has used open-source C2 frameworks, including Covenant.

T1078.003
Local Accounts

HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers.

T1078.004
Cloud Accounts

HAFNIUM has abused service principals in compromised environments to enable data exfiltration.

T1083
File and Directory Discovery

HAFNIUM has searched file contents on a compromised host.

View all 44 procedure examples

Software6

Campaigns0

None recorded.

References3

  1. Microsoft HAFNIUM March 2020 Open source
    MSTIC. (2021, March 2). HAFNIUM targeting Exchange Servers with 0-day exploits. Retrieved March 3, 2021.
  2. Microsoft Silk Typhoon MAR 2025 Open source
    Microsoft Threat Intelligence . (2025, March 5). Silk Typhoon targeting IT supply chain. Retrieved March 20, 2025.
  3. Volexity Exchange Marauder March 2021 Open source
    Gruzweig, J. et al. (2021, March 2). Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities. Retrieved March 3, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.