Meta tags:
Headings (most frequently used words):
hafnium, associated, group, descriptions, techniques, used, software, references, enterprise, layer,
Text of the page (most frequently used words):
#hafnium (52), has (46), enterprise (43), and (32), data (19), for (18), used (17), the (16), system (14), from (14), exchange (13), att (11), command (11), web (11), all (10), 2021 (10), march (10), microsoft (9), windows (9), discovery (9), compromised (9), software (8), retrieved (8), service (8), shell (8), domain (8), information (8), 001 (8), servers (7), access (7), account (7), files (7), cloud (7), accounts (7), 003 (7), including (7), scripting (6), interpreter (6), execution (6), management (6), credential (6), dumping (6), application (6), exfiltration (6), ics (5), mobile (5), none (5), techniques (5), exploitation (5), with (5), name (5), services (5), network (5), layer (5), server (5), password (5), gather (5), host (5), group (5), victim (5), 002 (5), mitre (4), use (4), groups (4), detection (4), threat (4), day (4), vulnerabilities (4), silk (4), typhoon (4), operation (4), marauder (4), remote (4), tool (4), transfer (4), create (4), tickets (4), binary (4), proxy (4), protocol (4), file (4), environments (4), credentials (4), collected (4), tools (4), addresses (4), 005 (4), targeted (4), email (4), devices (4), infrastructure (4), version (4), 2026 (3), domains (3), cti (3), defenses (3), intelligence (3), 2023 (3), 2022 (3), scheduled (3), zero (3), active (3), multiple (3), task (3), modify (3), token (3), process (3), steal (3), security (3), lsass (3), memory (3), ntds (3), protocols (3), compromise (3), covenant (3), component (3), directory (3), local (3), china (3), abused (3), stolen (3), associated (3), repositories (3), open (3), collection (3), sharepoint (3), encoding (3), acquire (3), corporation (2), are (2), policy (2), contact (2), reset (2), resources (2), reference (2), campaigns (2), components (2), analytics (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), december (2), team (2), response (2), tarrask (2), malware (2), defense (2), october (2), july (2), names (2), 2025 (2), targeting (2), exploits (2), references (2), masquerading (2), location (2), hide (2), artifacts (2), manipulation (2), smb (2), admin (2), lateral (2), instrumentation (2), forge (2), kerberos (2), secrets (2), non (2), standard (2), powershell (2), internet (2), facing (2), ingress (2), brute (2), force (2), chopper (2), aspxspy (2), principals (2), valid (2), 004 (2), privilege (2), user (2), using (2), via (2), rundll32 (2), shells (2), public (2), search (2), hidden (2), target (2), details (2), edge (2), premises (2), storage (2), msgraph (2), export (2), mailbox (2), logs (2), machine (2), exfiltrate (2), onedrive (2), stores (2), 006 (2), created (2), covert (2), networks (2), obfuscate (2), communications (2), botnet (2), archive (2), leased (2), virtual (2), private (2), qualys (2), g0125 (2), ckcon (2), person (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, filters, sub, guidance, preventing, detecting, hunting, log4j, vulnerability, april, uses, tasks, evasion, june, bromiley, eoin, miller, defending, against, analyzing, attacker, behavior, post, how, actors, november, supply, chain, gruzweig, mstic, job, registry, masquerade, match, legitimate, resource, impersonation, theft, s1011, shares, psexec, s0029, ccache, kerberoasting, lsa, manager, sniffing, resolution, poisoning, relay, adversary, middle, impacket, s0357, mshta, installutil, regsvr32, port, asymmetric, cryptography, encrypted, channel, control, following, s1155, packing, obfuscated, timestomp, indicator, removal, guessing, s0020, s0073, enable, authority, t1078, administrative, permissions, alternate, authentication, material, t1550, api, keys, pam, app, providers, companies, downstream, customer, trusted, relationship, t1199, whoami, owner, t1033, checked, connectivity, attempts, google, com, ping, connection, ipinfo, configuration, t1016, load, malicious, dlls, 011, t1218, deployed, simpleseesharp, sportsball, t1505, discovered, leaked, corporate, github, code, websites, t1593, enumerated, controllers, nltest, dclist, net, computers, t1018, enumerate, processes, tasklist, t1057, copies, database, dit, dump, procdump, t1003, tcp, t1095, downloaded, nishang, powercat, onto, t1105, directories, t1564, obtained, publicly, accessible, gathered, fully, qualified, fqdns, environment, t1590, mail, users, they, intended, identity, t1589, interacted, office, 365, tenants, regarding, client, configurations, t1592, searched, contents, t1083, unpatched, applications, elevate, organizations, escalation, t1068, exploited, versions, exploit, t1190, exfiltrated, sharing, sites, mega, over, t1567, t1114, cleared, actor, performed, actions, clear, event, disable, t1685, t1005, t1213, exfitrated, t1530, ascii, traffic, t1132, moved, laterally, passwords, azure, key, vaults, t1555, t1136, t1584, execute, commands, cmd, exe, power, module, set, oabvirtualdirectorypowershell, t1059, gained, initial, through, spray, attacks, spraying, t1110, automated, t1119, zip, winrar, compress, utility, t1560, source, frameworks, t1071, acquired, incorporated, into, operated, vps, united, states, t1583, granted, privileges, default, t1098, view, download, navigator, layers, description, descriptions, live, permalink, last, modified, daniyal, naeem, matt, brenton, zurich, insurance, mayuresh, dani, harshal, tupsamudre, vinayak, wadhwa, safe, contributors, likely, state, sponsored, cyber, espionage, operating, out, that, been, since, least, january, primarily, targets, entities, across, number, industry, sectors, infectious, disease, researchers, law, firms, higher, education, institutions, contractors, think, tanks, ngos, intial, demonstrated, ability, quickly, operationalize, identified, home, join, mclean, hotel, can, found, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, about, get, started, detections,
Text of the page (random words):
hafnium operation exchange marauder silk typhoon group g0125 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home groups hafnium hafnium hafnium is a likely state sponsored cyber espionage group operating out of china that has been active since at least january 2021 hafnium primarily targets entities in the us across a number of industry sectors including infectious disease researchers law firms higher education institutions defense contractors policy think tanks and ngos hafnium has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices 1 2 3 id g0125 ⓘ associated groups operation exchange marauder silk typhoon contributors daniyal naeem bt security matt brenton zurich insurance group mayuresh dani qualys harshal tupsamudre qualys vinayak wadhwa safe security version 3 0 created 03 march 2021 last modified 31 july 2026 version permalink live version associated group descriptions name description operation exchange marauder 2 silk typhoon 4 3 att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1098 account manipulation hafnium has granted privileges to domain accounts and reset the password for default admin accounts 2 3 enterprise t1583 003 acquire infrastructure virtual private server hafnium has operated from leased virtual private servers vps in the united states 1 005 acquire infrastructure botnet hafnium has incorporated leased devices into covert networks to obfuscate communications 3 006 acquire infrastructure web services hafnium has acquired web services for use in c2 and exfiltration 1 enterprise t1071 001 application layer protocol web protocols hafnium has used open source c2 frameworks including covenant 1 enterprise t1560 001 archive collected data archive via utility hafnium has used 7 zip and winrar to compress stolen files for exfiltration 1 2 enterprise t1119 automated collection hafnium has used msgraph to exfiltrate data from email onedrive and sharepoint 3 enterprise t1110 003 brute force password spraying hafnium has gained initial access through password spray attacks 3 enterprise t1059 001 command and scripting interpreter powershell hafnium has used the exchange power shell module set oabvirtualdirectorypowershell to export mailbox data 1 2 003 command and scripting interpreter windows command shell hafnium has used cmd exe to execute commands on the victim s machine 5 enterprise t1584 005 compromise infrastructure botnet hafnium has used compromised devices in covert networks to obfuscate communications 3 enterprise t1136 002 create account domain account hafnium has created domain accounts 2 3 enterprise t1555 006 credentials from password stores cloud secrets management stores hafnium has moved laterally from on premises environments to steal passwords from azure key vaults 3 enterprise t1132 001 data encoding standard encoding hafnium has used ascii encoding for c2 traffic 1 enterprise t1530 data from cloud storage hafnium has exfitrated data from onedrive 3 enterprise t1213 002 data from information repositories sharepoint hafnium has abused compromised credentials to exfiltrate data from sharepoint 3 enterprise t1005 data from local system hafnium has collected data and files from a compromised machine 5 3 enterprise t1685 005 disable or modify tools clear windows event logs hafnium has cleared actor performed actions from logs 3 enterprise t1114 002 email collection remote email collection hafnium has used web shells and msgraph to export mailbox data 1 2 3 enterprise t1567 002 exfiltration over web service exfiltration to cloud storage hafnium has exfiltrated data to file sharing sites including mega 1 enterprise t1190 exploit public facing application hafnium has exploited multiple vulnerabilities to compromise edge devices and on premises versions of microsoft exchange server 1 2 6 7 8 3 enterprise t1068 exploitation for privilege escalation hafnium has targeted unpatched applications to elevate access in targeted organizations 3 enterprise t1083 file and directory discovery hafnium has searched file contents on a compromised host 5 enterprise t1592 004 gather victim host information client configurations hafnium has interacted with office 365 tenants to gather details regarding target s environments 1 enterprise t1589 002 gather victim identity information email addresses hafnium has collected e mail addresses for users they intended to target 2 enterprise t1590 gather victim network information hafnium gathered the fully qualified domain names fqdns for targeted exchange servers in the victim s environment 2 005 ip addresses hafnium has obtained ip addresses for publicly accessible exchange servers 2 enterprise t1564 001 hide artifacts hidden files and directories hafnium has hidden files on a compromised host 5 enterprise t1105 ingress tool transfer hafnium has downloaded malware and tools including nishang and powercat onto a compromised host 1 5 enterprise t1095 non application layer protocol hafnium has used tcp for c2 1 enterprise t1003 001 os credential dumping lsass memory hafnium has used procdump to dump the lsass process memory 1 2 5 003 os credential dumping ntds hafnium has stolen copies of the active directory database ntds dit 2 3 enterprise t1057 process discovery hafnium has used tasklist to enumerate processes 5 enterprise t1018 remote system discovery hafnium has enumerated domain controllers using net group domain computers and nltest dclist 5 enterprise t1593 003 search open websites domains code repositories hafnium has discovered leaked corporate credentials on public repositories including github 3 enterprise t1505 003 server software component web shell hafnium has deployed multiple web shells on compromised servers including simpleseesharp sportsball china chopper and aspxspy 1 2 6 7 5 3 enterprise t1218 011 system binary proxy execution rundll32 hafnium has used rundll32 to load malicious dlls 2 enterprise t1016 system network configuration discovery hafnium has collected ip information via ipinfo 5 001 internet connection discovery hafnium has checked for network connectivity from a compromised host using ping including attempts to contact google com 5 enterprise t1033 system owner user discovery hafnium has used whoami to gather user information 5 enterprise t1199 trusted relationship hafnium has used stolen api keys and credentials associated with privilege access management pam cloud app providers and cloud data management companies to access downstream customer environments 3 enterprise t1550 001 use alternate authentication material application access token hafnium has abused service principals with administrative permissions for data exfiltration 3 enterprise t1078 003 valid accounts local accounts hafnium has used the nt authority system account to create files on exchange servers 6 004 valid accounts cloud accounts hafnium has abused service principals in compromised environments to enable data exfiltration 3 software id name references techniques s0073 aspxspy 2 server software component web shell s0020 china chopper 2 6 5 application layer protocol web protocols brute force password guessing command and scripting interpreter windows command shell data from local system file and directory discovery indicator removal timestomp ingress tool transfer network service discovery obfuscated files or information software packing server software component web shell s1155 covenant hafnium used covenant for command and control following compromise of internet facing servers 1 3 application layer protocol web protocols command and scripting interpreter powershell command and scripting interpreter windows command shell encrypted channel asymmetric cryptography non standard port system binary proxy execution regsvr32 system binary proxy execution installutil system binary proxy execution mshta system information discovery windows management instrumentation s0357 impacket 7 adversary in the middle name resolution poisoning and smb relay lateral tool transfer network sniffing os credential dumping ntds os credential dumping lsass memory os credential dumping security account manager os credential dumping lsa secrets steal or forge kerberos tickets kerberoasting steal or forge kerberos tickets ccache files system services service execution windows management instrumentation s0029 psexec 2 create account domain account create or modify system process windows service lateral tool transfer remote services smb windows admin shares system services service execution s1011 tarrask 7 access token manipulation token impersonation theft command and scripting interpreter windows command shell hide artifacts masquerading match legitimate resource name or location masquerading masquerade task or service modify registry scheduled task job scheduled task references mstic 2021 march 2 hafnium targeting exchange servers with 0 day exploits retrieved march 3 2021 gruzweig j et al 2021 march 2 operation exchange marauder active exploitation of multiple zero day microsoft exchange vulnerabilities retrieved march 3 2021 microsoft threat intelligence 2025 march 5 silk typhoon targeting it supply chain retrieved march 20 2025 microsoft 2023 july 12 how microsoft names threat actors retrieved november 17 2023 eoin miller 2021 march 23 defending against the zero day analyzing attacker behavior post exploitation of microsoft exchange retrieved october 27 2022 bromiley m et al 2021 march 4 detection and response to exploitation of microsoft exchange zero day vulnerabilities retrieved march 9 2021 microsoft threat intelligence team detection and response team 2022 april 12 tarrask malware uses scheduled tasks for defense evasion retrieved june 1 2022 microsoft threat intelligence 2021 december 11 guidance for preventing detecting and hunting for exploitation of the log4j 2 vulnerability retrieved december 7 2023 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|