If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/groups/G0125 - HAFNIUM, Operation Exchange Ma.

site address: attack.mitre.org/groups/G0125 redirected to: attack.mitre.org/groups/G0125

site title: HAFNIUM, Operation Exchange Marauder, Silk Typhoon, Group G0125 MITRE ATT&CK®

Our opinion (on Thursday 27 August 2026 13:46:48 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

hafnium, associated, group, descriptions, techniques, used, software, references, enterprise, layer,

Text of the page (most frequently used words):
#hafnium (52), has (46), enterprise (43), and (32), data (19), for (18), used (17), the (16), system (14), from (14), exchange (13), att (11), command (11), web (11), all (10), 2021 (10), march (10), microsoft (9), windows (9), discovery (9), compromised (9), software (8), retrieved (8), service (8), shell (8), domain (8), information (8), 001 (8), servers (7), access (7), account (7), files (7), cloud (7), accounts (7), 003 (7), including (7), scripting (6), interpreter (6), execution (6), management (6), credential (6), dumping (6), application (6), exfiltration (6), ics (5), mobile (5), none (5), techniques (5), exploitation (5), with (5), name (5), services (5), network (5), layer (5), server (5), password (5), gather (5), host (5), group (5), victim (5), 002 (5), mitre (4), use (4), groups (4), detection (4), threat (4), day (4), vulnerabilities (4), silk (4), typhoon (4), operation (4), marauder (4), remote (4), tool (4), transfer (4), create (4), tickets (4), binary (4), proxy (4), protocol (4), file (4), environments (4), credentials (4), collected (4), tools (4), addresses (4), 005 (4), targeted (4), email (4), devices (4), infrastructure (4), version (4), 2026 (3), domains (3), cti (3), defenses (3), intelligence (3), 2023 (3), 2022 (3), scheduled (3), zero (3), active (3), multiple (3), task (3), modify (3), token (3), process (3), steal (3), security (3), lsass (3), memory (3), ntds (3), protocols (3), compromise (3), covenant (3), component (3), directory (3), local (3), china (3), abused (3), stolen (3), associated (3), repositories (3), open (3), collection (3), sharepoint (3), encoding (3), acquire (3), corporation (2), are (2), policy (2), contact (2), reset (2), resources (2), reference (2), campaigns (2), components (2), analytics (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), december (2), team (2), response (2), tarrask (2), malware (2), defense (2), october (2), july (2), names (2), 2025 (2), targeting (2), exploits (2), references (2), masquerading (2), location (2), hide (2), artifacts (2), manipulation (2), smb (2), admin (2), lateral (2), instrumentation (2), forge (2), kerberos (2), secrets (2), non (2), standard (2), powershell (2), internet (2), facing (2), ingress (2), brute (2), force (2), chopper (2), aspxspy (2), principals (2), valid (2), 004 (2), privilege (2), user (2), using (2), via (2), rundll32 (2), shells (2), public (2), search (2), hidden (2), target (2), details (2), edge (2), premises (2), storage (2), msgraph (2), export (2), mailbox (2), logs (2), machine (2), exfiltrate (2), onedrive (2), stores (2), 006 (2), created (2), covert (2), networks (2), obfuscate (2), communications (2), botnet (2), archive (2), leased (2), virtual (2), private (2), qualys (2), g0125 (2), ckcon (2), person (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, filters, sub, guidance, preventing, detecting, hunting, log4j, vulnerability, april, uses, tasks, evasion, june, bromiley, eoin, miller, defending, against, analyzing, attacker, behavior, post, how, actors, november, supply, chain, gruzweig, mstic, job, registry, masquerade, match, legitimate, resource, impersonation, theft, s1011, shares, psexec, s0029, ccache, kerberoasting, lsa, manager, sniffing, resolution, poisoning, relay, adversary, middle, impacket, s0357, mshta, installutil, regsvr32, port, asymmetric, cryptography, encrypted, channel, control, following, s1155, packing, obfuscated, timestomp, indicator, removal, guessing, s0020, s0073, enable, authority, t1078, administrative, permissions, alternate, authentication, material, t1550, api, keys, pam, app, providers, companies, downstream, customer, trusted, relationship, t1199, whoami, owner, t1033, checked, connectivity, attempts, google, com, ping, connection, ipinfo, configuration, t1016, load, malicious, dlls, 011, t1218, deployed, simpleseesharp, sportsball, t1505, discovered, leaked, corporate, github, code, websites, t1593, enumerated, controllers, nltest, dclist, net, computers, t1018, enumerate, processes, tasklist, t1057, copies, database, dit, dump, procdump, t1003, tcp, t1095, downloaded, nishang, powercat, onto, t1105, directories, t1564, obtained, publicly, accessible, gathered, fully, qualified, fqdns, environment, t1590, mail, users, they, intended, identity, t1589, interacted, office, 365, tenants, regarding, client, configurations, t1592, searched, contents, t1083, unpatched, applications, elevate, organizations, escalation, t1068, exploited, versions, exploit, t1190, exfiltrated, sharing, sites, mega, over, t1567, t1114, cleared, actor, performed, actions, clear, event, disable, t1685, t1005, t1213, exfitrated, t1530, ascii, traffic, t1132, moved, laterally, passwords, azure, key, vaults, t1555, t1136, t1584, execute, commands, cmd, exe, power, module, set, oabvirtualdirectorypowershell, t1059, gained, initial, through, spray, attacks, spraying, t1110, automated, t1119, zip, winrar, compress, utility, t1560, source, frameworks, t1071, acquired, incorporated, into, operated, vps, united, states, t1583, granted, privileges, default, t1098, view, download, navigator, layers, description, descriptions, live, permalink, last, modified, daniyal, naeem, matt, brenton, zurich, insurance, mayuresh, dani, harshal, tupsamudre, vinayak, wadhwa, safe, contributors, likely, state, sponsored, cyber, espionage, operating, out, that, been, since, least, january, primarily, targets, entities, across, number, industry, sectors, infectious, disease, researchers, law, firms, higher, education, institutions, contractors, think, tanks, ngos, intial, demonstrated, ability, quickly, operationalize, identified, home, join, mclean, hotel, can, found, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, about, get, started, detections,


Text of the page (random words):
hafnium operation exchange marauder silk typhoon group g0125 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home groups hafnium hafnium hafnium is a likely state sponsored cyber espionage group operating out of china that has been active since at least january 2021 hafnium primarily targets entities in the us across a number of industry sectors including infectious disease researchers law firms higher education institutions defense contractors policy think tanks and ngos hafnium has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices 1 2 3 id g0125 ⓘ associated groups operation exchange marauder silk typhoon contributors daniyal naeem bt security matt brenton zurich insurance group mayuresh dani qualys harshal tupsamudre qualys vinayak wadhwa safe security version 3 0 created 03 march 2021 last modified 31 july 2026 version permalink live version associated group descriptions name description operation exchange marauder 2 silk typhoon 4 3 att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1098 account manipulation hafnium has granted privileges to domain accounts and reset the password for default admin accounts 2 3 enterprise t1583 003 acquire infrastructure virtual private server hafnium has operated from leased virtual private servers vps in the united states 1 005 acquire infrastructure botnet hafnium has incorporated leased devices into covert networks to obfuscate communications 3 006 acquire infrastructure web services hafnium has acquired web services for use in c2 and exfiltration 1 enterprise t1071 001 application layer protocol web protocols hafnium has used open source c2 frameworks including covenant 1 enterprise t1560 001 archive collected data archive via utility hafnium has used 7 zip and winrar to compress stolen files for exfiltration 1 2 enterprise t1119 automated collection hafnium has used msgraph to exfiltrate data from email onedrive and sharepoint 3 enterprise t1110 003 brute force password spraying hafnium has gained initial access through password spray attacks 3 enterprise t1059 001 command and scripting interpreter powershell hafnium has used the exchange power shell module set oabvirtualdirectorypowershell to export mailbox data 1 2 003 command and scripting interpreter windows command shell hafnium has used cmd exe to execute commands on the victim s machine 5 enterprise t1584 005 compromise infrastructure botnet hafnium has used compromised devices in covert networks to obfuscate communications 3 enterprise t1136 002 create account domain account hafnium has created domain accounts 2 3 enterprise t1555 006 credentials from password stores cloud secrets management stores hafnium has moved laterally from on premises environments to steal passwords from azure key vaults 3 enterprise t1132 001 data encoding standard encoding hafnium has used ascii encoding for c2 traffic 1 enterprise t1530 data from cloud storage hafnium has exfitrated data from onedrive 3 enterprise t1213 002 data from information repositories sharepoint hafnium has abused compromised credentials to exfiltrate data from sharepoint 3 enterprise t1005 data from local system hafnium has collected data and files from a compromised machine 5 3 enterprise t1685 005 disable or modify tools clear windows event logs hafnium has cleared actor performed actions from logs 3 enterprise t1114 002 email collection remote email collection hafnium has used web shells and msgraph to export mailbox data 1 2 3 enterprise t1567 002 exfiltration over web service exfiltration to cloud storage hafnium has exfiltrated data to file sharing sites including mega 1 enterprise t1190 exploit public facing application hafnium has exploited multiple vulnerabilities to compromise edge devices and on premises versions of microsoft exchange server 1 2 6 7 8 3 enterprise t1068 exploitation for privilege escalation hafnium has targeted unpatched applications to elevate access in targeted organizations 3 enterprise t1083 file and directory discovery hafnium has searched file contents on a compromised host 5 enterprise t1592 004 gather victim host information client configurations hafnium has interacted with office 365 tenants to gather details regarding target s environments 1 enterprise t1589 002 gather victim identity information email addresses hafnium has collected e mail addresses for users they intended to target 2 enterprise t1590 gather victim network information hafnium gathered the fully qualified domain names fqdns for targeted exchange servers in the victim s environment 2 005 ip addresses hafnium has obtained ip addresses for publicly accessible exchange servers 2 enterprise t1564 001 hide artifacts hidden files and directories hafnium has hidden files on a compromised host 5 enterprise t1105 ingress tool transfer hafnium has downloaded malware and tools including nishang and powercat onto a compromised host 1 5 enterprise t1095 non application layer protocol hafnium has used tcp for c2 1 enterprise t1003 001 os credential dumping lsass memory hafnium has used procdump to dump the lsass process memory 1 2 5 003 os credential dumping ntds hafnium has stolen copies of the active directory database ntds dit 2 3 enterprise t1057 process discovery hafnium has used tasklist to enumerate processes 5 enterprise t1018 remote system discovery hafnium has enumerated domain controllers using net group domain computers and nltest dclist 5 enterprise t1593 003 search open websites domains code repositories hafnium has discovered leaked corporate credentials on public repositories including github 3 enterprise t1505 003 server software component web shell hafnium has deployed multiple web shells on compromised servers including simpleseesharp sportsball china chopper and aspxspy 1 2 6 7 5 3 enterprise t1218 011 system binary proxy execution rundll32 hafnium has used rundll32 to load malicious dlls 2 enterprise t1016 system network configuration discovery hafnium has collected ip information via ipinfo 5 001 internet connection discovery hafnium has checked for network connectivity from a compromised host using ping including attempts to contact google com 5 enterprise t1033 system owner user discovery hafnium has used whoami to gather user information 5 enterprise t1199 trusted relationship hafnium has used stolen api keys and credentials associated with privilege access management pam cloud app providers and cloud data management companies to access downstream customer environments 3 enterprise t1550 001 use alternate authentication material application access token hafnium has abused service principals with administrative permissions for data exfiltration 3 enterprise t1078 003 valid accounts local accounts hafnium has used the nt authority system account to create files on exchange servers 6 004 valid accounts cloud accounts hafnium has abused service principals in compromised environments to enable data exfiltration 3 software id name references techniques s0073 aspxspy 2 server software component web shell s0020 china chopper 2 6 5 application layer protocol web protocols brute force password guessing command and scripting interpreter windows command shell data from local system file and directory discovery indicator removal timestomp ingress tool transfer network service discovery obfuscated files or information software packing server software component web shell s1155 covenant hafnium used covenant for command and control following compromise of internet facing servers 1 3 application layer protocol web protocols command and scripting interpreter powershell command and scripting interpreter windows command shell encrypted channel asymmetric cryptography non standard port system binary proxy execution regsvr32 system binary proxy execution installutil system binary proxy execution mshta system information discovery windows management instrumentation s0357 impacket 7 adversary in the middle name resolution poisoning and smb relay lateral tool transfer network sniffing os credential dumping ntds os credential dumping lsass memory os credential dumping security account manager os credential dumping lsa secrets steal or forge kerberos tickets kerberoasting steal or forge kerberos tickets ccache files system services service execution windows management instrumentation s0029 psexec 2 create account domain account create or modify system process windows service lateral tool transfer remote services smb windows admin shares system services service execution s1011 tarrask 7 access token manipulation token impersonation theft command and scripting interpreter windows command shell hide artifacts masquerading match legitimate resource name or location masquerading masquerade task or service modify registry scheduled task job scheduled task references mstic 2021 march 2 hafnium targeting exchange servers with 0 day exploits retrieved march 3 2021 gruzweig j et al 2021 march 2 operation exchange marauder active exploitation of multiple zero day microsoft exchange vulnerabilities retrieved march 3 2021 microsoft threat intelligence 2025 march 5 silk typhoon targeting it supply chain retrieved march 20 2025 microsoft 2023 july 12 how microsoft names threat actors retrieved november 17 2023 eoin miller 2021 march 23 defending against the zero day analyzing attacker behavior post exploitation of microsoft exchange retrieved october 27 2022 bromiley m et al 2021 march 4 detection and response to exploitation of microsoft exchange zero day vulnerabilities retrieved march 9 2021 microsoft threat intelligence team detection and response team 2022 april 12 tarrask malware uses scheduled tasks for defense evasion retrieved june 1 2022 microsoft threat intelligence 2021 december 11 guidance for preventing detecting and hunting for exploitation of the log4j 2 vulnerability retrieved december 7 2023 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 152 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
151-152


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 1 references to other resources (not html/xhtml )

 attack.mitre.org/groups/G0125/G0125-e___.json  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/groups/G0125
X-GitHub-Request-Id E92C:15C6E9:BA1643:BB9A98:6A903FC8
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Thu, 27 Aug 2026 13:46:48 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290034-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787838409.634090,VS0,VE100
Vary Accept-Encoding
X-Fastly-Request-ID 9ff290a9bf0a0578deaf38e4ff061034909ece53
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/groups/G0125/
access-control-allow-origin *
expires Thu, 27 Aug 2026 13:56:48 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 5EB0:15BD:118A9FD2:11ADE9BB:6A903FC8
x-github-edge-region fra
accept-ranges bytes
age 0
date Thu, 27 Aug 2026 13:46:48 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290044-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787838409.761772,VS0,VE102
vary Accept-Encoding
x-fastly-request-id 813fd2a71fe79ff70a8ca1808b630d9cd9dcd608
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:07 GMT
access-control-allow-origin *
etag W/ 6a75ea87-1de55
expires Thu, 27 Aug 2026 13:56:48 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id CFE0:28505E:BB7355:BCF7DB:6A903FC8
x-github-edge-region fra
accept-ranges bytes
age 0
date Thu, 27 Aug 2026 13:46:48 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290044-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787838409.872071,VS0,VE118
vary Accept-Encoding
x-fastly-request-id c121aeebc70367f12df6a5de9ca6efb4e05e5a40
content-length 13161

Meta Tags

title="HAFNIUM, Operation Exchange Marauder, Silk Typhoon, Group G0125 | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size13161
load time (s)0.588457
redirect count2
speed download22382
server IP 185.199.111.153
* all occurrences of the string "http://" have been changed to "htt???/"