Skip to content

G0125

attack.mitre.org April 27, 2026

HAFNIUM is a likely state- cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices. [1] [2] [3]

HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts. [2] [3]

HAFNIUM has operated from leased virtual private servers (VPS) in the United States. [1]

HAFNIUM has incorporated leased devices into covert networks to obfuscate communications. [3]

HAFNIUM has acquired web services for use in C2 and exfiltration. [1]

HAFNIUM has used open-source C2 frameworks, including Covenant . [1]

HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration. [1] [2]

HAFNIUM has used MSGraph to exfiltrate data from email, OneDrive, and SharePoint. [3]

HAFNIUM has gained initial access through password spray attacks. [3]

HAFNIUM has used the Exchange Power Shell module Set-OabVirtualDirectoryPowerShell to export mailbox data. [1] [2]

HAFNIUM has used cmd.exe to execute commands on the victim's machine. [5]

HAFNIUM has used compromised devices in covert networks to obfuscate communications. [3]

HAFNIUM has created domain accounts. [2] [3]

HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults. [3]

HAFNIUM has used ASCII encoding for C2 traffic. [1]

HAFNIUM has exfitrated data from OneDrive. [3]

HAFNIUM has abused compromised credentials to exfiltrate data from SharePoint. [3]

HAFNIUM has collected data and files from a compromised machine. [5] [3]

HAFNIUM has used web shells and MSGraph to export mailbox data. [1] [2] [3]

HAFNIUM has exfiltrated data to file sharing sites, including MEGA. [1]

HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server. [1] [2] [6] [7] [8] [3]

HAFNIUM has targeted unpatched applications to elevate access in targeted organizations. [3]

HAFNIUM has searched file contents on a compromised host. [5]

HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments. [1]

HAFNIUM has collected e-mail addresses for users they intended to target. [2]

HAFNIUM gathered the fully qualified domain names (FQDNs) for targeted Exchange servers in the victim's environment. [2]

HAFNIUM has obtained IP addresses for publicly-accessible Exchange servers. [2]

HAFNIUM has hidden files on a compromised host. [5]

HAFNIUM has cleared actor-performed actions from logs. [3]

HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host. [1] [5]

HAFNIUM has used TCP for C2. [1]

HAFNIUM has used procdump to dump the LSASS process memory. [1] [2] [5]

HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT). [2] [3]

HAFNIUM has used tasklist to enumerate processes. [5]

HAFNIUM has enumerated domain controllers using net group "Domain computers" and nltest /dclist . [5]

HAFNIUM has discovered leaked corporate credentials on public repositories including GitHub. [3]

HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper , and ASPXSpy . [1] [2] [6] [7] [5] [3]

HAFNIUM has used rundll32 to load malicious DLLs. [2]

HAFNIUM has collected IP information via IPInfo. [5]

HAFNIUM has checked for network connectivity from a compromised host using ping , including attempts to google[.]com . [5]

HAFNIUM has used whoami to gather user information. [5]

HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments. [3]

HAFNIUM has abused service principals with administrative permissions for data exfiltration. [3]

HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers. [6]

HAFNIUM has abused service principals in compromised environments to enable data exfiltration. [3]