Microsoft Threat Intelligence . (2025, March 5). Silk Typhoon targeting IT supply chain. Retrieved March 20, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupHAFNIUM | HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT). |
| T1005 Data from Local System |
GroupHAFNIUM | HAFNIUM has collected data and files from a compromised machine. |
| T1068 Exploitation for Privilege Escalation |
GroupHAFNIUM | HAFNIUM has targeted unpatched applications to elevate access in targeted organizations. |
| T1078.004 Cloud Accounts |
GroupHAFNIUM | HAFNIUM has abused service principals in compromised environments to enable data exfiltration. |
| T1098 Account Manipulation |
GroupHAFNIUM | HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts. |
| T1110.003 Password Spraying |
GroupHAFNIUM | HAFNIUM has gained initial access through password spray attacks. |
| T1114.002 Remote Email Collection |
GroupHAFNIUM | HAFNIUM has used web shells and MSGraph to export mailbox data. |
| T1119 Automated Collection |
GroupHAFNIUM | HAFNIUM has used MSGraph to exfiltrate data from email, OneDrive, and SharePoint. |
| T1136.002 Domain Account |
GroupHAFNIUM | HAFNIUM has created domain accounts. |
| T1190 Exploit Public-Facing Application |
GroupHAFNIUM | HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server. |
| T1199 Trusted Relationship |
GroupHAFNIUM | HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments. |
| T1213.002 Sharepoint |
GroupHAFNIUM | HAFNIUM has abused compromised credentials to exfiltrate data from SharePoint. |
| T1505.003 Web Shell |
GroupHAFNIUM | HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy. |
| T1530 Data from Cloud Storage |
GroupHAFNIUM | HAFNIUM has exfitrated data from OneDrive. |
| T1550.001 Application Access Token |
GroupHAFNIUM | HAFNIUM has abused service principals with administrative permissions for data exfiltration. |
| T1555.006 Cloud Secrets Management Stores |
GroupHAFNIUM | HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults. |
| T1583.005 Botnet |
GroupHAFNIUM | HAFNIUM has incorporated leased devices into covert networks to obfuscate communications. |
| T1584.005 Botnet |
GroupHAFNIUM | HAFNIUM has used compromised devices in covert networks to obfuscate communications. |
| T1593.003 Code Repositories |
GroupHAFNIUM | HAFNIUM has discovered leaked corporate credentials on public repositories including GitHub. |
| T1685.005 Clear Windows Event Logs |
GroupHAFNIUM | HAFNIUM has cleared actor-performed actions from logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.