HAFNIUM
ATK233G0125Operation Exchange MarauderRed Dev 13Silk TyphoonMURKY PANDA
HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. Microsoft Threat Intelligence Center (MSTIC) attributes this campaign with high confidence to HAFNIUM, a group assessed to be state-sponsored and operating out of China,… Source: MISP
Attributed country: CN according to MISP
Activity on Jábega · 12 weeks
1 stories · first seen on 7 Oct 2026 · last seen on 7 Oct 2026
News
- US posts $10 million reward for accused Chinese ‘Hafnium’ hackerThe Record · 7 Oct 2026
MITRE ATT&CK techniques
Reconnaissance
T1589.002Email Addresses 1 Sigma rulesT1590Gather Victim Network Information 4 Sigma rulesT1590.005IP AddressesT1592.004Client Configurations 3 Sigma rulesT1593.003Code Repositories 2 Sigma rules
Resource Development
Initial Access
T1078.003Local Accounts 4 Sigma rulesT1078.004Cloud Accounts 35 Sigma rulesT1190Exploit Public-Facing Application 40 Sigma rulesT1199Trusted Relationship 1 Sigma rules
Execution
Persistence
T1098Account Manipulation 36 Sigma rulesT1136.002Domain Account 3 Sigma rulesT1505.003Web Shell 33 Sigma rules
Privilege Escalation
Credential Access
T1003.001LSASS Memory 40 Sigma rulesT1003.003NTDS 23 Sigma rulesT1110.003Password SprayingT1555.006Cloud Secrets Management Stores
Discovery
T1016System Network Configuration Discovery 4 Sigma rulesT1016.001Internet Connection DiscoveryT1018Remote System Discovery 9 Sigma rulesT1033System Owner/User Discovery 26 Sigma rulesT1057Process Discovery 3 Sigma rulesT1083File and Directory Discovery 17 Sigma rules
Lateral Movement
Collection
T1005Data from Local System 12 Sigma rulesT1114.002Remote Email CollectionT1119Automated Collection 5 Sigma rulesT1213.002SharepointT1530Data from Cloud StorageT1560.001Archive via Utility 10 Sigma rules
Command and Control
T1071.001Web Protocols 39 Sigma rulesT1095Non-Application Layer Protocol 3 Sigma rulesT1105Ingress Tool Transfer 40 Sigma rulesT1132.001Standard Encoding 4 Sigma rules
Exfiltration
Stealth
Defense impairment
Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗