ATT&CKReferencesMicrosoft HAFNIUM March 2020

Microsoft HAFNIUM March 2020

MSTIC. (2021, March 2). HAFNIUM targeting Exchange Servers with 0-day exploits. Retrieved March 3, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupHAFNIUM

HAFNIUM has used procdump to dump the LSASS process memory.

T1059.001
PowerShell
GroupHAFNIUM

HAFNIUM has used the Exchange Power Shell module Set-OabVirtualDirectoryPowerShell to export mailbox data.

T1071.001
Web Protocols
GroupHAFNIUM

HAFNIUM has used open-source C2 frameworks, including Covenant.

T1095
Non-Application Layer Protocol
GroupHAFNIUM

HAFNIUM has used TCP for C2.

T1105
Ingress Tool Transfer
GroupHAFNIUM

HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host.

T1114.002
Remote Email Collection
GroupHAFNIUM

HAFNIUM has used web shells and MSGraph to export mailbox data.

T1132.001
Standard Encoding
GroupHAFNIUM

HAFNIUM has used ASCII encoding for C2 traffic.

T1190
Exploit Public-Facing Application
GroupHAFNIUM

HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server.

T1505.003
Web Shell
GroupHAFNIUM

HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy.

T1560.001
Archive via Utility
GroupHAFNIUM

HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration.

T1567.002
Exfiltration to Cloud Storage
GroupHAFNIUM

HAFNIUM has exfiltrated data to file sharing sites, including MEGA.

T1583.003
Virtual Private Server
GroupHAFNIUM

HAFNIUM has operated from leased virtual private servers (VPS) in the United States.

T1583.006
Web Services
GroupHAFNIUM

HAFNIUM has acquired web services for use in C2 and exfiltration.

T1592.004
Client Configurations
GroupHAFNIUM

HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.