Microsoft said the China-linked Hafnium threat actor used a malware tool called Tarrask to maintain persistence on compromised Windows systems by abusing scheduled tasks. According to Microsoft Threat Intelligence Center, the malware creates scheduled tasks and related registry entries, then deletes the Security Descriptor value from the TaskCache\Tree registry path, causing the task to disappear from both Windows Task Scheduler and the schtasks command-line utility while remaining active on the host.
In one observed intrusion, Hafnium created a task named "WinUpdate" to restore command-and-control connectivity after interruptions. Microsoft said the activity targeted organizations in the telecommunications, internet service provider, and data services sectors between August 2021 and February 2022, showing the group expanding beyond the victim set associated with its earlier Microsoft Exchange exploitation and underscoring its detailed knowledge of Windows internals for stealth and defense evasion.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft Threat Intelligence Center publicly linked Hafnium to the Tarrask malware and described how it hides scheduled tasks by deleting the Security Descriptor value from the TaskCache\Tree registry path. The disclosure highlighted the malware's stealthy persistence and defense-evasion method on Windows systems.
Microsoft said the China-linked Hafnium threat actor used the Tarrask malware to maintain persistence on compromised Windows systems while targeting organizations in the telecommunications, internet service provider, and data services sectors. The activity was observed between August 2021 and February 2022 and included creation of a hidden scheduled task named "WinUpdate" to restore command-and-control connectivity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.