HAFNIUM
ATK233G0125Operation Exchange MarauderRed Dev 13Silk TyphoonMURKY PANDA
HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. Microsoft Threat Intelligence Center (MSTIC) attributes this campaign with high confidence to HAFNIUM, a group assessed to be state-sponsored and operating out of China,… Fuente: MISP
País atribuido: CN según MISP
Actividad en Jábega · 12 semanas
1 noticias · vista por primera vez el 7 oct 2026 · la última, el 7 oct 2026
Noticias
- US posts $10 million reward for accused Chinese ‘Hafnium’ hackerThe Record · 7 oct 2026
Técnicas MITRE ATT&CK
Reconocimiento
T1589.002Email Addresses 1 reglas SigmaT1590Gather Victim Network Information 4 reglas SigmaT1590.005IP AddressesT1592.004Client Configurations 3 reglas SigmaT1593.003Code Repositories 2 reglas Sigma
Preparación de recursos
Acceso inicial
T1078.003Local Accounts 4 reglas SigmaT1078.004Cloud Accounts 35 reglas SigmaT1190Exploit Public-Facing Application 40 reglas SigmaT1199Trusted Relationship 1 reglas Sigma
Ejecución
Persistencia
T1098Account Manipulation 36 reglas SigmaT1136.002Domain Account 3 reglas SigmaT1505.003Web Shell 33 reglas Sigma
Escalada de privilegios
Acceso a credenciales
T1003.001LSASS Memory 40 reglas SigmaT1003.003NTDS 23 reglas SigmaT1110.003Password SprayingT1555.006Cloud Secrets Management Stores
Descubrimiento
T1016System Network Configuration Discovery 4 reglas SigmaT1016.001Internet Connection DiscoveryT1018Remote System Discovery 9 reglas SigmaT1033System Owner/User Discovery 26 reglas SigmaT1057Process Discovery 3 reglas SigmaT1083File and Directory Discovery 17 reglas Sigma
Movimiento lateral
Recopilación
T1005Data from Local System 12 reglas SigmaT1114.002Remote Email CollectionT1119Automated Collection 5 reglas SigmaT1213.002SharepointT1530Data from Cloud StorageT1560.001Archive via Utility 10 reglas Sigma
Mando y control
T1071.001Web Protocols 39 reglas SigmaT1095Non-Application Layer Protocol 3 reglas SigmaT1105Ingress Tool Transfer 40 reglas SigmaT1132.001Standard Encoding 4 reglas Sigma
Exfiltración
Stealth
Defense impairment
Relaciones por coaparición en noticias, no atribución. Fuentes: MISP galaxy, MITRE ATT&CK y SigmaHQ. attack.mitre.org ↗