HAFNIUM is a suspected Chinese state-sponsored threat actor targeting US defense and research sectors by exploiting internet-facing servers.
Analyst brief
HAFNIUM (also tracked as Silk Typhoon, MURKY PANDA) is a suspected state-sponsored threat actor operating out of China. It primarily targets infectious disease researchers, defense contractors, law firms, and NGOs in the United States. Initial access is achieved by exploiting vulnerabilities in internet-facing servers, followed by deploying web shells like ASPXSpy and China Chopper, and leveraging the Covenant C2 framework. Defenders should prioritize monitoring for password spraying, credential dumping from LSASS, and exfiltration to cloud storage.
HAFNIUM
ATK233G0125Operation Exchange Marauder
unknown
HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. Microsoft Threat Intelligence Center (MSTIC) attributes this campaign with high confidence to HAFNIUM, a group assessed to be state-sponsored and operating out of China, based on observed victimology, tactics and procedures. HAFNIUM has previously compromised victims by exploiting vulnerabilities in internet-facing servers, and has used legitimate open-source frameworks, like Covenant, for command and control. Once they’ve gained access to a victim network, HAFNIUM typically exfiltrates data to file sharing sites like MEGA.In campaigns unrelated to these vulnerabilities, Microsoft has observed HAFNIUM interacting with victim Office 365 tenants. While they are often unsuccessful in compromising customer accounts, this reconnaissance activity helps the adversary identify more details about their targets’ environments. HAFNIUM operates primarily from leased virtual private servers (VPS) in the United States.
Monitor for suspicious activities related to clearing Windows Event Logs.
FAQ2
What sectors does HAFNIUM target?+
HAFNIUM primarily targets infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs in the United States.
How does HAFNIUM achieve initial access?+
HAFNIUM achieves initial access by exploiting vulnerabilities in internet-facing servers, and then leverages the Covenant C2 framework along with web shells like ASPXSpy and China Chopper.