Skip to main content
Mallory
China16 malware familiesExploits CVEs in the wild

hafnium

Also known asHAFNIUMMURKY PANDAOperation Exchange MarauderSilk Typhoontimmy

Hafnium, now mapped by Microsoft to Silk Typhoon, is a China-attributed state-sponsored threat actor. The provided content explicitly describes Silk Typhoon as also known as Hafnium, and notes Microsoft’s 2024 taxonomy change mapping HAFNIUM to Silk Typhoon. Reported aliases in the content include Murky Panda, Operation Exchange Marauder, Silk Typhoon, and Timmy. The actor is best known for exploiting four zero-day vulnerabilities in on-premises Microsoft Exchange Server in 2021. Microsoft said Hafnium operated from China, commonly using leased virtual private servers in the United States, and targeted U.S.-based organizations to steal information. Victim sectors and organizations explicitly mentioned in the content include universities and higher education, defense contractors, law firms and legal services, infectious-disease researchers, policy think tanks, NGOs and international aid organizations, state and local governments, healthcare, finance, and the U.S. Department of the Treasury. Additional reporting in the content states that, as of 2024, Silk Typhoon was focused on using stolen credentials to gain access to networks operated by state and local governments. The content attributes to Hafnium/Silk Typhoon a range of post-compromise behaviors and techniques. These include impersonating authorized users after Exchange exploitation; establishing remote control of compromised servers; deploying web shells and other malware; collecting data and files from compromised machines; exporting mailbox data via the Exchange PowerShell module Set-OabVirtualDirectoryPowerShell; abusing service principals to enable data exfiltration; and exfiltrating data to file-sharing sites including MEGA. ATT&CK-style examples in the content also state that HAFNIUM used cmd.exe to execute commands, tasklist to enumerate processes, whoami to gather user information, net group "Domain computers" and nltest /dclist for domain controller discovery, ASCII encoding for C2 traffic, open-source C2 frameworks including Covenant, and hidden scheduled-task persistence via the Tarrask malware. Microsoft Threat Intelligence Center linked Hafnium to Tarrask, describing its use of hidden scheduled tasks, including a task named "WinUpdate," to re-establish command-and-control connectivity while evading Task Scheduler and schtasks visibility. Beyond the 2021 Exchange activity, the content states that Hafnium/Silk Typhoon targeted telecommunications, internet service provider, and data services entities between August 2021 and February 2022, and that Silk Typhoon was linked to the December 2024 U.S. Treasury breach. The content also states that Silk Typhoon has targeted defense, healthcare, higher education, legal services, NGOs, and global IT supply chains, and abused remote-access tools and cloud applications for initial access. One cited report also says employees of i-Soon were named alongside members of China’s APT27, aka Silk Typhoon, but the broader content consistently treats Hafnium/Silk Typhoon as the same China-linked espionage actor.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics61 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595×3
Active Scanning
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.003
Virtual Private Server
T1608
Stage Capabilities
T1608.001
Upload Malware
T1608.002
Upload Tool
TA0001
Initial Access
6 techniques
T1078×6
Valid Accounts
T1078.004×2
Cloud Accounts
T1133
External Remote Services
T1190×20
Exploit Public-Facing Application
T1195×2
Supply Chain Compromise
T1199
Trusted Relationship
T1566
Phishing
TA0002
Execution
4 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003×3
Windows Command Shell
T1059.004
Unix Shell
T1129×2
Shared Modules
T1203
Exploitation for Client Execution
TA0003
Persistence
5 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1078×6
Valid Accounts
T1078.004×2
Cloud Accounts
T1133
External Remote Services
T1136
Create Account
T1505
Server Software Component
T1505.003×8
Web Shell
TA0004
Privilege Escalation
4 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1068
Exploitation for Privilege Escalation
T1078×6
Valid Accounts
T1078.004×2
Cloud Accounts
T1134
Access Token Manipulation
TA0005
Stealth
3 techniques
T1078×6
Valid Accounts
T1078.004×2
Cloud Accounts
T1134
Access Token Manipulation
T1564×2
Hide Artifacts
TA0006
Credential Access
2 techniques
T1040
Network Sniffing
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
7 techniques
T1012
Query Registry
T1018×2
Remote System Discovery
T1033
System Owner/User Discovery
T1040
Network Sniffing
T1057
Process Discovery
T1482
Domain Trust Discovery
T1580
Cloud Infrastructure Discovery
TA0008
Lateral Movement
1 technique
T1021×2
Remote Services
TA0009
Collection
4 techniques
T1005×5
Data from Local System
T1039
Data from Network Shared Drive
T1114×4
Email Collection
T1213×5
Data from Information Repositories
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1090
Proxy
T1090.002×2
External Proxy
T1105
Ingress Tool Transfer
T1132×2
Data Encoding
TA0010
Exfiltration
2 techniques
T1048
Exfiltration Over Alternative Protocol
T1567
Exfiltration Over Web Service
T1567.002×3
Exfiltration to Cloud Storage
WEAPONIZED

Associated vulnerabilities

20 CVEs this actor has used in observed campaigns. 20 of them exploited in the wild.

CVE-2024-12356Unauthenticated RCE in BeyondTrust PRA and RSIn the wildEvidence7

The flaw is a variant of CVE-2024-12356, which was linked to the December 2024 hack of the U.S. Treasury Department by Silk Typhoon, a state-linked actor backed by China.

CVE-2021-26855ProxyLogon SSRF in Microsoft Exchange ServerIn the wildEvidence6

Hafnium gained prominence in 2021 for the campaign targeting the Microsoft vulnerability known as ProxyLogon. The bug was used to steal troves of U.S. government emails and other data from large companies.

CVE-2021-27065ProxyLogon post-auth arbitrary file write in Microsoft Exchange ServerIn the wildEvidence6

Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-27065 - Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-26858Microsoft Exchange Server post-auth arbitrary file write (ProxyLogon)In the wildEvidence5

Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-26858 - Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-26857Microsoft Exchange Unified Messaging insecure deserialization RCEIn the wildEvidence4

Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-26857 - Microsoft Exchange Server Remote Code Execution Vulnerability

15 more CVEs tied to this actor tracked in Mallory.

IOCS

Observables

69 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping43

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal16

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs20

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables69

Domains, IPs, and hashes tied to this actor, refreshed continuously.