HAFNIUM, also tracked as Silk Typhoon, is a Chinese state-linked cyber espionage threat actor known for targeting internet-facing enterprise infrastructure and rapidly operationalizing zero-day and n-day vulnerabilities for initial access. The group is widely associated with the large-scale 2021 exploitation of on-premises Microsoft Exchange Server vulnerabilities known as ProxyLogon, a campaign that enabled mass compromise of tens of thousands of organizations worldwide and commonly involved deployment of ASPX web shells on exposed servers. Reported aliases include Murky Panda, Operation Exchange Marauder, Timmy, and Silk Typhoon. The actor has historically focused on espionage objectives, including collection from email and collaboration environments and access to sensitive government, policy, and enterprise information. Victimology has included government entities, policy and sanctions-related organizations, and a broad range of organizations operating self-hosted messaging and remote administration infrastructure. Activity attributed to Silk Typhoon has also been linked to exploitation of BeyondTrust Remote Support zero-days in an intrusion connected to compromise of the U.S. Treasury and related U.S. government entities. Observed tradecraft includes exploitation of public-facing applications, especially Exchange and remote support platforms; use of server-side request forgery within exploit chains; deployment of web shells for persistence and command execution; PowerShell-based execution; privilege escalation; installation or abuse of Windows services for persistence; file and directory discovery on compromised hosts; and data exfiltration from cloud-connected enterprise services. The group has been reported searching file contents on compromised systems and using Microsoft Graph to exfiltrate data from email, OneDrive, and SharePoint. HAFNIUM is notable for combining traditional espionage objectives with high-tempo, vulnerability-driven operations that can scale far beyond narrowly targeted intrusions. Its campaigns illustrate a pattern of leveraging newly disclosed or zero-day flaws in widely deployed enterprise software to obtain broad access, establish footholds, and then selectively pursue intelligence collection from compromised environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
22 CVEs this actor has used in observed campaigns. 22 of them exploited in the wild.
Silk Typhoon is believed to have exploited two zero-days (CVE-2024-12356 and CVE-2024-12686) to breach BeyondTrust's systems and use a stolen API key to compromise 17 Remote Support SaaS instances, including the Treasury's instance.
The only IOC we've found is this scan for CVE 2021 26855 mere hours before we patched on March 1st.
Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-27065 - Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft havaitsi ja korjasi useamman nollapäivähaavoittuvuuden, joita käytettiin kohdistetuissa hyökkäyksissä Microsoft Exchange Server -sähköpostipalvelimia kohtaan... CVE-2021-26858 - Microsoft Exchange Server Remote Code Execution Vulnerability
Silk Typhoon is believed to have exploited two zero-days (CVE-2024-12356 and CVE-2024-12686) to breach BeyondTrust's systems and use a stolen API key to compromise 17 Remote Support SaaS instances, including the Treasury's instance.
17 more CVEs tied to this actor tracked in Mallory.
73 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a large-scale, vulnerability-driven smash-and-grab campaign across tens of thousands of machines, described as nearly deception-free and severe enough to prompt a U.S. court-authorized remediation action.
Chinese state-backed cyberespionage activity that exploited BeyondTrust zero-days and a stolen API key to compromise BeyondTrust systems and multiple Remote Support SaaS instances, including U.S. Treasury-related targets.
Previously exploited BeyondTrust Remote Support zero-days in a high-profile intrusion connected to the U.S. Treasury compromise.
Listed as an annotation/tag associated with privilege escalation techniques in the detection content; no campaign or activity by the group is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.