HAFNIUM
Also reported as Silk Typhoon, Operation Exchange Marauder, Red Dev 13, MURKY PANDA, ATK233 and 3 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1071.001 3 reports in ATT&CK
- T1059.003 2 reports in ATT&CK
- T1074.001 2 reports reports only
- T1083 2 reports in ATT&CK
- T1087.002 2 reports reports only
- T1190 2 reports in ATT&CK
- T1505.003 2 reports in ATT&CK
- T1003 1 report reports only
- T1003.001 1 report in ATT&CK
- T1003.002 1 report reports only
Show all 61 techniques Show fewer
- T1005 1 report in ATT&CK
- T1007 1 report reports only
- T1016 1 report in ATT&CK
- T1018 1 report in ATT&CK
- T1021.001 1 report reports only
- T1033 1 report in ATT&CK
- T1041 1 report reports only
- T1047 1 report reports only
- T1048 1 report reports only
- T1055 1 report reports only
- T1057 1 report in ATT&CK
- T1059 1 report reports only
- T1059.001 1 report in ATT&CK
- T1059.005 1 report reports only
- T1059.007 1 report reports only
- T1071 1 report reports only
- T1074 1 report reports only
- T1078.002 1 report reports only
- T1078.003 1 report in ATT&CK
- T1082 1 report reports only
- T1087 1 report reports only
- T1087.001 1 report reports only
- T1090.001 1 report reports only
- T1098 1 report in ATT&CK
- T1105 1 report in ATT&CK
- T1134.001 1 report reports only
- T1135 1 report reports only
- T1203 1 report reports only
- T1218 1 report reports only
- T1218.007 1 report reports only
- T1505 1 report reports only
- T1518 1 report reports only
- T1518.001 1 report reports only
- T1531 1 report reports only
- T1552.001 1 report reports only
- T1560.001 1 report in ATT&CK
- T1570 1 report reports only
- T1572 1 report reports only
- T1583 1 report reports only
- T1583.003 1 report in ATT&CK
- T1587 1 report reports only
- T1587.001 1 report reports only
- T1587.004 1 report reports only
- T1588 1 report reports only
- T1588.001 1 report reports only
- T1588.002 1 report reports only
- T1588.005 1 report reports only
- T1588.006 1 report reports only
- T1595 1 report reports only
- T1595.001 1 report reports only
- T1595.002 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-3900 KEV
- CVE-2013-5947
- CVE-2013-7389
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0062
- CVE-2015-0554
Show all 158 CVEs Show fewer
- CVE-2015-1701 KEV ransomware
- CVE-2015-2051 KEV
- CVE-2015-7248
- CVE-2016-0099 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-10271 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2018-0802 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-18913
- CVE-2018-8440 KEV ransomware
- CVE-2018-8639 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-11634 KEV ransomware
- CVE-2019-1458 KEV ransomware
- CVE-2019-16759 KEV
- CVE-2019-16920 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-5591 KEV ransomware
- CVE-2019-7481 KEV ransomware
- CVE-2020-0601 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-10148 KEV
- CVE-2020-10189 KEV
- CVE-2020-1040 KEV
- CVE-2020-12271 KEV ransomware
- CVE-2020-12812 KEV ransomware
- CVE-2020-1350 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-16875
- CVE-2020-171324
- CVE-2020-17530 KEV
- CVE-2020-2551 KEV
- CVE-2020-3125
- CVE-2020-36198
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8234
- CVE-2020-8260 KEV
- CVE-2020-8515 KEV
- CVE-2021-1497 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-20016 KEV ransomware
- CVE-2021-20090 KEV
- CVE-2021-20655
- CVE-2021-21972 KEV ransomware
- CVE-2021-2198
- CVE-2021-22005 KEV ransomware
- CVE-2021-22205 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-22941 KEV ransomware
- CVE-2021-22986 KEV ransomware
- CVE-2021-24085
- CVE-2021-25323
- CVE-2021-25324
- CVE-2021-25325
- CVE-2021-26084 KEV ransomware
- CVE-2021-26412
- CVE-2021-26854
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-2701
- CVE-2021-27065 KEV ransomware
- CVE-2021-27078
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-27104 KEV ransomware
- CVE-2021-27857
- CVE-2021-28310 KEV
- CVE-2021-28799 KEV ransomware
- CVE-2021-29855
- CVE-2021-30657 KEV
- CVE-2021-31166 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-31805
- CVE-2021-31955 KEV
- CVE-2021-31956 KEV
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-33766 KEV
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35247 KEV
- CVE-2021-35394 KEV
- CVE-2021-36260 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-38647 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41773 KEV ransomware
- CVE-2021-42013 KEV ransomware
- CVE-2021-42237 KEV ransomware
- CVE-2021-42321 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-44428
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1388 KEV ransomware
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-24112 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-34305
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2023-3519 KEV ransomware
- CVE-2023-46747 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-8190 KEV
- CVE-2024-8963 KEV
- CVE-2024-9379 KEV
- CVE-2024-9380 KEV
- CVE-2024-9381
- CVE-2025-0282 KEV ransomware
- CVE-2025-31324 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2026-22769 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CHINACHOPPER (Malware Family)
Show all 149 reports Show fewer
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
Attacks on industrial control systems using ShadowPad _ Kaspersky ICS CERT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Attacks on industrial control systems using ShadowPad _ Kaspersky ICS CERT
-
Attacks on industrial control systems using ShadowPad
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attacks on industrial control systems using ShadowPad
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
Tarrask malware uses scheduled tasks for defense evasion
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Tarrask malware uses scheduled tasks for defense evasion
-
Tarrask malware uses scheduled tasks for defense evasion
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tarrask malware uses scheduled tasks for defense evasion
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Threat Report 2022
-
The APT Fallout of Vulnerabilities such as ProxyLogon, OGNL Injection, and log4shell
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The APT Fallout of Vulnerabilities such as ProxyLogon, OGNL Injection, and log4shell
-
Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
-
Russian cyberattacks pose greater risk to governments and other insights from our annual report
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyberattacks pose greater risk to governments and other insights from our annual report
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
China's Microsoft Hack May Have Had A Bigger Purpose Than Just Spying
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China's Microsoft Hack May Have Had A Bigger Purpose Than Just Spying
-
DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
-
DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
-
UK and allies hold Chinese state responsible for a pervasive pattern of hacking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UK and allies hold Chinese state responsible for a pervasive pattern of hacking
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12021
-
APT_trends_report_Q1_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2021_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q1 2021
-
Could the Microsoft Exchange breach be stopped-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Could the Microsoft Exchange breach be stopped-
-
The Unseen One- Hades Ransomware Gang or Hafnium
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Unseen One- Hades Ransomware Gang or Hafnium
-
Imperva Observes Hive of Activity Following Hafnium Microsoft Exchange Disclosures
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Imperva Observes Hive of Activity Following Hafnium Microsoft Exchange Disclosures
-
Web Shell Threat Hunting with Azure Sentinel
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Web Shell Threat Hunting with Azure Sentinel
-
CVE-2021-26855- Microsoft Exchange Server-Side Request Forgery
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2021-26855- Microsoft Exchange Server-Side Request Forgery
-
HAFNIUM, China Chopper and ASP.NET Runtime
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HAFNIUM, China Chopper and ASP.NET Runtime
-
How China’s Devastating Microsoft Hack Puts Us All at Risk
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How China’s Devastating Microsoft Hack Puts Us All at Risk
-
Detection and Investigation Using Devo- HAFNIUM 0-day Exploits on Microsoft Exchange Service
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detection and Investigation Using Devo- HAFNIUM 0-day Exploits on Microsoft Exchange Service
-
Microsoft Exchange Server Attack Timeline
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Exchange Server Attack Timeline
-
Exploits on Organizations Worldwide Tripled after Microsoft’s Revelation of Four Zero-days
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exploits on Organizations Worldwide Tripled after Microsoft’s Revelation of Four Zero-days
-
Update - Detection and Response for HAFNIUM Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Update - Detection and Response for HAFNIUM Activity
-
You Don't Know the HAFNIUM of it...
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor You Don't Know the HAFNIUM of it...
-
Norway parliament data stolen in Microsoft Exchange attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Norway parliament data stolen in Microsoft Exchange attack
-
Examining Exchange Exploitation and its Lessons for Defenders
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Examining Exchange Exploitation and its Lessons for Defenders
-
Tactics, Techniques, and Procedures (TTPs) Used by HAFNIUM to Target Microsoft Exchange Servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tactics, Techniques, and Procedures (TTPs) Used by HAFNIUM to Target Microsoft Exchange Servers
-
Exchange servers under siege from at least 10 APT groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exchange servers under siege from at least 10 APT groups
-
Microsoft Exchange server exploitation- how to detect, mitigate, and stay calm
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Exchange server exploitation- how to detect, mitigate, and stay calm
-
Reproducing the Microsoft Exchange Proxylogon Exploit Chain
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Reproducing the Microsoft Exchange Proxylogon Exploit Chain
-
Microsoft Exchange attacks cause panic as criminals go shell collecting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Exchange attacks cause panic as criminals go shell collecting
-
Hafnium – Active Exploitation of Microsoft Exchange and Lateral Movement
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hafnium – Active Exploitation of Microsoft Exchange and Lateral Movement
-
Hafnium Update- Continued Microsoft Exchange Server Exploitation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hafnium Update- Continued Microsoft Exchange Server Exploitation
-
How Symantec Stops Microsoft Exchange Server Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Symantec Stops Microsoft Exchange Server Attacks
-
Analyzing Attacks Against Microsoft Exchange Server With China Chopper Webshells
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Attacks Against Microsoft Exchange Server With China Chopper Webshells
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Security scripts
-
Microsoft Exchange Zero Days - Mitigations and Detections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Exchange Zero Days - Mitigations and Detections
-
Scan for HAFNIUM Exploitation Evidence with THOR Lite
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Scan for HAFNIUM Exploitation Evidence with THOR Lite
-
Hafnium Exchange Vuln Detection - KQL
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hafnium Exchange Vuln Detection - KQL
-
Chinese Hacking Spree Hit an ‘Astronomical’ Number of Victims
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Hacking Spree Hit an ‘Astronomical’ Number of Victims
-
HAFNIUM- Advice about the new nation-state attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HAFNIUM- Advice about the new nation-state attack
-
Detection and Response for HAFNIUM Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detection and Response for HAFNIUM Activity
-
Detection and Response to Exploitation of Microsoft Exchange Zero-Day Vulnerabilities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detection and Response to Exploitation of Microsoft Exchange Zero-Day Vulnerabilities
-
Detecting HAFNIUM Exchange Server Zero-Day Activity in Splunk
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting HAFNIUM Exchange Server Zero-Day Activity in Splunk
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HAFNIUM
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Exchange Marauder- Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities
-
New nation-state cyberattacks (HAFNIUM)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New nation-state cyberattacks (HAFNIUM)
-
HAFNIUM targeting Exchange Servers with 0-day exploits
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HAFNIUM targeting Exchange Servers with 0-day exploits
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Exchange Marauder_ Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities _ Volexity
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor New nation-state cyberattacks
-
Multiple Security Updates Released for Exchange Server – updated March 8, 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Multiple Security Updates Released for Exchange Server – updated March 8, 2021
-
HAFNIUM targeting Exchange Servers with 0-day exploits - Microsoft Security
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HAFNIUM targeting Exchange Servers with 0-day exploits - Microsoft Security
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
Newest first. Details opens the report in Explore.