HAFNIUM — APT Profile

HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.

Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.

Also tracked as

Operation Exchange Marauder, Silk Typhoon, ATK233, G0125, Red Dev 13, MURKY PANDA

IntelFusions coverage (2)

Tools & malware

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions