Overview 17 indicators
HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.
| domain | 16 | G0125-domain.txt |
| ipv4 | 1 | G0125.json |
Techniques 44 ATT&CK
Open in ATT&CK Navigator → or download the layer (44 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.003 NTDS
- T1005 Data from Local System
- T1016 System Network Configuration Discovery
- T1016.001 Internet Connection Discovery
- T1018 Remote System Discovery
- T1033 System Owner/User Discovery
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1068 Exploitation for Privilege Escalation
- T1071.001 Web Protocols
- T1078.003 Local Accounts
- T1078.004 Cloud Accounts
- T1083 File and Directory Discovery
- T1095 Non-Application Layer Protocol
- T1098 Account Manipulation
- T1105 Ingress Tool Transfer
- T1110.003 Password Spraying
- T1114.002 Remote Email Collection
- T1119 Automated Collection
- T1132.001 Standard Encoding
- T1136.002 Domain Account
- T1190 Exploit Public-Facing Application
- T1199 Trusted Relationship
- T1213.002 Sharepoint
- T1218.011 Rundll32
- T1505.003 Web Shell
- T1530 Data from Cloud Storage
- T1550.001 Application Access Token
- T1555.006 Cloud Secrets Management Stores
- T1560.001 Archive via Utility
- T1564.001 Hidden Files and Directories
- T1567.002 Exfiltration to Cloud Storage
- T1583.003 Virtual Private Server
- T1583.005 Botnet
- T1583.006 Web Services
- T1584.005 Botnet
- T1589.002 Email Addresses
- T1590 Gather Victim Network Information
- T1590.005 IP Addresses
- T1592.004 Client Configurations
- T1593.003 Code Repositories
- T1685.005 Clear Windows Event Logs
Software 6
Principal sources 6 reports
Ranked by how many of this actor's indicators each report brought in.
- 14twitter.com/Max_Mal_/status/1480284003617882121
- 2microsoft.com/security/blog/2021/03/02/hafnium-target…
- 2twitter.com/BushidoToken/status/1369273531867992064
- 2virustotal.com/gui/file/62842cffd1c663ac2b2abe85a9fd48…
- 1twitter.com/resecurity_com/status/13771371020940984…
- 1infosecurity-magazine.com/news/hades-ransomware-linked-hafnium
Related groups 2
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 17 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
twitter.com/Max_Mal_/status/1480284003617882121
back.estonine.com bk.estonine.com does-no-exist33.estonine.com e.estonine.com indicate.estonine.com inducate.estonine.com load.estonine.com log.estonine.com moon.estonine.com pslog.estonine.com sk.estonine.com sploit.estonine.com task.estonine.com -
twitter.com/resecurity_com/status/13771371020940984… · infosecurity-magazine.com/news/hades-ransomware-linked-hafnium
bingoshow.xyz -
twitter.com/Max_Mal_/status/1480284003617882121
p.estonine.com -
microsoft.com/security/blog/2021/03/02/hafnium-target… · twitter.com/BushidoToken/status/1369273531867992064 · virustotal.com/gui/file/62842cffd1c663ac2b2abe85a9fd48…
domain shelltools-1254394685.cos.ap-shanghai.myqcloud.com ipv4 101.37.76.66:5000
Further reading 10
- attack.mitre.org/groups/G0125
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- microsoft.com/en-us/security/blog/2025/03/05/silk-typ…
- microsoft.com/security/blog/2021/03/02/hafnium-target…
- volexity.com/blog/2021/03/02/active-exploitation-of-…
- virustotal.com/gui/file/62842cffd1c663ac2b2abe85a9fd48…
- infosecurity-magazine.com/news/hades-ransomware-linked-hafnium
- twitter.com/BushidoToken/status/1369273531867992064
- twitter.com/Max_Mal_/status/1480284003617882121
- twitter.com/resecurity_com/status/13771371020940984…