HAFNIUM
G01252 reportsAnalyst assessment — key judgments
- Signature techniques: T1213.002 (Sharepoint), T1588.006 (Vulnerabilities), T1684 (Social Engineering).
- Primary targeting: US, AE, CN, TW.
- Steady activity: 1 report(s) in last 30d vs 1 prior (+0%).
- Recent movement: 7 new technique(s), 2 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 100% of 7 observed techniques (0 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
Movement — last 30 days
Vulnerabilities in this actor's reporting · 2
- CVE-2025-20337KEV1 rpt
- CVE-2025-5777KEV1 rpt
Overview
HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.(Citation: Microsoft HAFNIUM March 2020)(Citation: Volexity Exchange Marauder March 2021)(Citation: Microsoft Silk Typhoon MAR 2025)
ATT&CK technique matrix
- T1213.002 · Sharepointconf 601
- T1588.006 · Vulnerabilitiesconf 601
- T1684 · Social Engineeringconf 601
- T1593.001 · Social Mediaconf 601
- T1589.001 · Credentialsconf 601
- T1684.001 · Impersonationconf 601
- AML.T0073 · Impersonationconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|