Threat group.View on attack.mitre.org
HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
HAFNIUM has used |
| T1003.003 NTDS |
HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT). |
| T1005 Data from Local System |
HAFNIUM has collected data and files from a compromised machine. |
| T1016 System Network Configuration Discovery |
HAFNIUM has collected IP information via IPInfo. |
| T1016.001 Internet Connection Discovery |
HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`. |
| T1018 Remote System Discovery |
HAFNIUM has enumerated domain controllers using `net group "Domain computers"` and `nltest /dclist`. |
| T1033 System Owner/User Discovery |
HAFNIUM has used `whoami` to gather user information. |
| T1057 Process Discovery |
HAFNIUM has used `tasklist` to enumerate processes. |
| T1059.001 PowerShell |
HAFNIUM has used the Exchange Power Shell module |
| T1059.003 Windows Command Shell |
HAFNIUM has used `cmd.exe` to execute commands on the victim's machine. |
| T1068 Exploitation for Privilege Escalation |
HAFNIUM has targeted unpatched applications to elevate access in targeted organizations. |
| T1071.001 Web Protocols |
HAFNIUM has used open-source C2 frameworks, including Covenant. |
| T1078.003 Local Accounts |
HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers. |
| T1078.004 Cloud Accounts |
HAFNIUM has abused service principals in compromised environments to enable data exfiltration. |
| T1083 File and Directory Discovery |
HAFNIUM has searched file contents on a compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.