HAFNIUM, also tracked as Silk Typhoon, is a Chinese state-linked cyber espionage threat actor known for targeting internet-facing enterprise infrastructure and rapidly operationalizing zero-day and n-day vulnerabilities for initial access. The group is widely associated with the large-scale 2021 exploitation of on-premises Microsoft Exchange Server vulnerabilities known as ProxyLogon, a campaign that enabled mass compromise of tens of thousands of organizations worldwide and commonly involved deployment of ASPX web shells on exposed servers. Reported aliases include Murky Panda, Operation Exchange Marauder, Timmy, and Silk Typhoon. The actor has historically focused on espionage objectives, including collection from email and collaboration environments and access to sensitive government, policy, and enterprise information. Victimology has included government entities, policy and sanctions-related organizations, and a broad range of organizations operating self-hosted messaging and remote administration infrastructure. Activity attributed to Silk Typhoon has also been linked to exploitation of BeyondTrust Remote Support zero-days in an intrusion connected to compromise of the U.S. Treasury and related U.S. government entities. Observed tradecraft includes exploitation of public-facing applications, especially Exchange and remote support platforms; use of server-side request forgery within exploit chains; deployment of web shells for persistence and command execution; PowerShell-based execution; privilege escalation; installation or abuse of Windows services for persistence; file and directory discovery on compromised hosts; and data exfiltration from cloud-connected enterprise services. The group has been reported searching file contents on compromised systems and using Microsoft Graph to exfiltrate data from email, OneDrive, and SharePoint. HAFNIUM is notable for combining traditional espionage objectives with high-tempo, vulnerability-driven operations that can scale far beyond narrowly targeted intrusions. Its campaigns illustrate a pattern of leveraging newly disclosed or zero-day flaws in widely deployed enterprise software to obtain broad access, establish footholds, and then selectively pursue intelligence collection from compromised environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.