HAFNIUM Group
HAFNIUM Group is referenced in the provided content as a threat actor associated with Splunk analytic stories and detections, including "Windows File Download Via PowerShell" and an analytic story listing "HAFNIUM Group" alongside other actor names. The content ties this reference to PowerShell-related behaviors and detections mapped to MITRE ATT&CK T1059.001, including file download via PowerShell and Nishang PowershellTCPOneLine. No additional high-confidence details about HAFNIUM Group’s origin, targets, sub-groups, or broader operations are directly provided in the content. The only alias directly provided is "hafnium_group."
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Associated vulnerabilities
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
The vulnerabilities recently being exploited were CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.
The vulnerabilities recently being exploited were CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.
The vulnerabilities recently being exploited were CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.
The vulnerabilities recently being exploited were CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named activity cluster in associated analytic stories related to this detection content.
Referenced in connection with PowerShell-based file download activity and Nishang PowerShell TCP one-liner behavior.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.