CNconfidence: 100G0125

HAFNIUMHAFNIUM

Also known as: ATK233 · G0125 · Operation Exchange Marauder · Red Dev 13 · Silk Typhoon · MURKY PANDA · HAFNIUM

Origin
CN
Known aliases
7
Attribution
100

Profile

HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. Microsoft Threat Intelligence Center (MSTIC) attributes this campaign with high confidence to HAFNIUM, a group assessed to be state-sponsored and operating out of China, based on observed victimology, tactics and procedures. HAFNIUM has previously compromised victims by exploiting vulnerabilities in internet-facing servers, and has used legitimate open-source frameworks, like Covenant, for command and control. Once they’ve gained access to a victim network, HAFNIUM typically exfiltrates data to file sharing sites like MEGA.In campaigns unrelated to these vulnerabilities, Microsoft has observed HAFNIUM interacting with victim Office 365 tenants. While they are often unsuccessful in compromising customer accounts, this reconnaissance activity helps the adversary identify more details about their targets’ environments. HAFNIUM operates primarily from leased virtual private servers (VPS) in the United States.

Aliases· 7

ATK233Operation Exchange MarauderRed Dev 13Silk TyphoonMURKY PANDAHAFNIUM
G0125

MITRE ATT&CK Group crosswalk

G0125

References

  1. https://attack.mitre.org/groups/G0125/
  2. https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers
  3. https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
  4. https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html
  5. https://www.reddit.com/r/msp/comments/lwmo5c/mass_exploitation_of_onprem_exchange_servers
  6. https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day
  7. https://twitter.com/ESETresearch/status/1366862946488451088
  8. https://www.fireeye.com/blog/threat-research/2021/03/detection-response-to-exploitation-of-microsoft-exchange-zero-day-vulnerabilities.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Storm-0062
Actor
Bahamut
Actor
POLONIUM
Actor
MUSTANG PANDA
Actor
TERBIUM
Actor
APT31
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.