HAFNIUM
Aliases: Operation Exchange Marauder, Silk Typhoon
HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.
Open interactive actor investigation
ATT&CK techniques
T1592.004
Client ConfigurationsT1105
Ingress Tool TransferT1583.006
Web ServicesT1560.001
Archive via UtilityT1005
Data from Local SystemT1033
System Owner/User DiscoveryT1059.003
Windows Command ShellT1057
Process DiscoveryT1003.001
LSASS MemoryT1590
Gather Victim Network InformationT1505.003
Web ShellT1589.002
Email AddressesT1567.002
Exfiltration to Cloud StorageT1114.002
Remote Email CollectionT1218.011
Rundll32T1078.003
Local AccountsT1059.001
PowerShellT1564.001
Hidden Files and DirectoriesT1016.001
Internet Connection DiscoveryT1016
System Network Configuration DiscoveryT1590.005
IP AddressesT1083
File and Directory DiscoveryT1003.003
NTDST1098
Account ManipulationT1136.002
Domain AccountT1071.001
Web ProtocolsT1018
Remote System DiscoveryT1190
Exploit Public-Facing ApplicationT1095
Non-Application Layer ProtocolT1132.001
Standard EncodingT1583.003
Virtual Private Server
Client ConfigurationsT1105
Ingress Tool TransferT1583.006
Web ServicesT1560.001
Archive via UtilityT1005
Data from Local SystemT1033
System Owner/User DiscoveryT1059.003
Windows Command ShellT1057
Process DiscoveryT1003.001
LSASS MemoryT1590
Gather Victim Network InformationT1505.003
Web ShellT1589.002
Email AddressesT1567.002
Exfiltration to Cloud StorageT1114.002
Remote Email CollectionT1218.011
Rundll32T1078.003
Local AccountsT1059.001
PowerShellT1564.001
Hidden Files and DirectoriesT1016.001
Internet Connection DiscoveryT1016
System Network Configuration DiscoveryT1590.005
IP AddressesT1083
File and Directory DiscoveryT1003.003
NTDST1098
Account ManipulationT1136.002
Domain AccountT1071.001
Web ProtocolsT1018
Remote System DiscoveryT1190
Exploit Public-Facing ApplicationT1095
Non-Application Layer ProtocolT1132.001
Standard EncodingT1583.003
Virtual Private Server