← All actors Recent activity

HAFNIUM G0125

HAFNIUM · Hade ransomware · TimosaraHackerTerm

Indicators
17
Source reports
6
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20212022

Overview 17 indicators

HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.

domain16G0125-domain.txt
ipv41G0125.json

Techniques 44 ATT&CK

Open in ATT&CK Navigator → or download the layer (44 techniques, layer 4.5)

Software 6

Principal sources 6 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 17 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 13 domain4 yrs ago

    twitter.com/Max_Mal_/status/1480284003617882121

    back.estonine.com
    bk.estonine.com
    does-no-exist33.estonine.com
    e.estonine.com
    indicate.estonine.com
    inducate.estonine.com
    load.estonine.com
    log.estonine.com
    moon.estonine.com
    pslog.estonine.com
    sk.estonine.com
    sploit.estonine.com
    task.estonine.com

  2. 1 domain5 yrs ago

    twitter.com/resecurity_com/status/13771371020940984… · infosecurity-magazine.com/news/hades-ransomware-linked-hafnium

    bingoshow.xyz

  3. 1 domain5 yrs ago

    twitter.com/Max_Mal_/status/1480284003617882121

    p.estonine.com

  4. 1 domain, 1 ipv45 yrs ago

    microsoft.com/security/blog/2021/03/02/hafnium-target… · twitter.com/BushidoToken/status/1369273531867992064 · virustotal.com/gui/file/62842cffd1c663ac2b2abe85a9fd48…

    domainshelltools-1254394685.cos.ap-shanghai.myqcloud.com
    ipv4101.37.76.66:5000

Further reading 10