Hafnium — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
15
occurrences
First Seen
October 29, 2025
Last Seen
July 23, 2026

Hafnium is a China-based APT group historically known for exploiting Microsoft Exchange Server vulnerabilities to gain initial access, establish persistence, and move laterally within target networks.

Overview

Hafnium is a China-based APT group historically known for exploiting Microsoft Exchange Server vulnerabilities to gain initial access, establish persistence, and move laterally within target networks. Its campaigns have underscored the ongoing risk to on-premises Exchange environments and the critical need for rapid patching, strong access controls, and robust monitoring to defend against such threats.

Related Threat Clusters

Recent Intelligence Reports

  • T1590 — attack.mitre.org · July 23, 2026
  • MITRE ATT&CK T1199 — attack.mitre.org · July 20, 2026
  • T1505.003 Web Shell — attack.mitre.org · May 13, 2026
  • Justice Department Announces Arrest Prolific Chinese State Sponsored Contract Hacker — www.justice.gov · April 29, 2026
  • G0125 — attack.mitre.org · April 27, 2026
  • Hacker who allegedly carried out cyberattacks for China is extradited to U.S. — Techcrunch · April 27, 2026
  • Italy extradites suspected Chinese hacker wanted by US authorities — Internazionale.It · April 27, 2026
  • Italy plans to send 'wanted' Chinese hacker to US authorities, sources say — Thenews.Pk · April 26, 2026

CVSS v3.1 Breakdown