HAFNIUM — APT Profile
HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Operation Exchange Marauder, Silk Typhoon, ATK233, G0125, Red Dev 13, MURKY PANDA
IntelFusions coverage (2)
- China-linked groups drive most state-backed attacks on tech firms 2026-06-10 · Nation-State
- HAFNIUM's ProxyLogon Chain Triggers 44,000 Exploitation Attempts from 1,600+ IPs Within Weeks of Disclosure 2026-02-16 · Nation-State
Tools & malware
- ASPXSpy Web Shell
- China Chopper Web Shell
- Covenant Post-Exploitation Framework
- Impacket Network Toolkit
- Nishang tool
- PowerCat tool
- procdump tool
- PsExec Remote Execution
- Tarrask Backdoor
Vendor research
- Silk Typhoon (HAFNIUM) nation-state actor profile Microsoft
- How Microsoft names threat actors Microsoft
- Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities Volexity
- Silk Typhoon targeting IT supply chain Microsoft
- HAFNIUM targeting Exchange Servers with 0-day exploits Microsoft
Countries linked to this actor
- China origin