HAFNIUM, now more commonly tracked by Microsoft as Silk Typhoon, is a China-linked state-sponsored cyber-espionage threat actor. The group is widely associated with intelligence collection operations against government entities, policy and regulatory organizations, defense-related targets, critical infrastructure, and other strategically significant sectors. It is best known for the large-scale 2021 exploitation of Microsoft Exchange Server vulnerabilities known as ProxyLogon, which enabled rapid compromise of tens of thousands of internet-facing servers worldwide. Aliases associated with this actor include Silk Typhoon, Hafnium, Hafnium Group, Murky Panda, Operation Exchange Marauder, and Timmy. In current industry usage, Silk Typhoon is generally the preferred name, while HAFNIUM remains the most recognizable historical label because of the Exchange intrusions. The actor has demonstrated a pattern of exploiting newly disclosed and zero-day vulnerabilities in externally exposed enterprise software to obtain initial access at scale, then transitioning to targeted post-exploitation for espionage. Reported operations linked to the group include exploitation of Microsoft Exchange Server vulnerabilities such as CVE-2021-26855 and later activity involving BeyondTrust Remote Support zero-days tied to compromise of U.S. Treasury-related systems. The group has also been associated with long-term access to critical infrastructure environments. Operationally, HAFNIUM/Silk Typhoon combines vulnerability exploitation with credential and mailbox access, abuse of legitimate administrative interfaces, and selective collection from high-value accounts. Observed tradecraft includes server-side exploitation of public-facing applications, privilege escalation, PowerShell-based execution, installation of web shells or other persistence mechanisms, enumeration of high-value mailboxes, and export or collection of email data through Exchange-related services and APIs. The actor is assessed to favor stealthy follow-on access after broad initial compromise, using valid accounts and native tooling where possible. The group’s targeting and behavior are consistent with strategic Chinese intelligence requirements rather than financially motivated crime. Its operations have repeatedly focused on information of diplomatic, economic, regulatory, and national-security value, and its campaigns illustrate a broader Chinese state practice of pairing mass exploitation opportunities with selective intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
22 CVEs this actor has used in observed campaigns. 22 of them exploited in the wild.
The only IOC we've found is this scan for CVE 2021 26855 mere hours before we patched on March 1st.
Silk Typhoon is believed to have exploited two zero-days (CVE-2024-12356 and CVE-2024-12686) to breach BeyondTrust's systems and use a stolen API key to compromise 17 Remote Support SaaS instances, including the Treasury's instance.
Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-27065 - Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-26858 - Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-26857 - Microsoft Exchange Server Remote Code Execution Vulnerability
17 more CVEs tied to this actor tracked in Mallory.
73 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked group maintaining long-term access to critical infrastructure including energy and water sectors.
Conducted a large-scale, vulnerability-driven smash-and-grab campaign across tens of thousands of machines, described as nearly deception-free and severe enough to prompt a U.S. court-authorized remediation action.
Chinese state-backed cyberespionage activity that exploited BeyondTrust zero-days and a stolen API key to compromise BeyondTrust systems and multiple Remote Support SaaS instances, including U.S. Treasury-related targets.
Previously exploited BeyondTrust Remote Support zero-days in a high-profile intrusion connected to the U.S. Treasury compromise.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.