MSTIC. (2021, March 2). HAFNIUM targeting Exchange Servers with 0-day exploits. Retrieved March 3, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupHAFNIUM | HAFNIUM has used |
| T1059.001 PowerShell |
GroupHAFNIUM | HAFNIUM has used the Exchange Power Shell module |
| T1071.001 Web Protocols |
GroupHAFNIUM | HAFNIUM has used open-source C2 frameworks, including Covenant. |
| T1095 Non-Application Layer Protocol |
GroupHAFNIUM | HAFNIUM has used TCP for C2. |
| T1105 Ingress Tool Transfer |
GroupHAFNIUM | HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host. |
| T1114.002 Remote Email Collection |
GroupHAFNIUM | HAFNIUM has used web shells and MSGraph to export mailbox data. |
| T1132.001 Standard Encoding |
GroupHAFNIUM | HAFNIUM has used ASCII encoding for C2 traffic. |
| T1190 Exploit Public-Facing Application |
GroupHAFNIUM | HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server. |
| T1505.003 Web Shell |
GroupHAFNIUM | HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy. |
| T1560.001 Archive via Utility |
GroupHAFNIUM | HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupHAFNIUM | HAFNIUM has exfiltrated data to file sharing sites, including MEGA. |
| T1583.003 Virtual Private Server |
GroupHAFNIUM | HAFNIUM has operated from leased virtual private servers (VPS) in the United States. |
| T1583.006 Web Services |
GroupHAFNIUM | HAFNIUM has acquired web services for use in C2 and exfiltration. |
| T1592.004 Client Configurations |
GroupHAFNIUM | HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.