Hafnium
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Hafnium is a threat actor tracked under that alias and is publicly associated with operations originating from China. The actor has been described in multiple reports as a state‑sponsored group whose activities are motivated by the collection of political and economic intelligence rather than financial gain or disruptive intent. Hafnium’s targeting pattern includes government institutions, financial regulators, and international organizations across Southeast Asia, Latin America, Europe, and North America, reflecting a focus on entities that hold sensitive diplomatic, regulatory, or financial data. The actor’s strategic objective, as explicitly noted in the attribution of the ASEAN mail server compromise, is to gather intelligence that supports geopolitical and economic interests linked to China’s broader regional initiatives.
In terms of tactics, Hafnium repeatedly gains initial access through the exploitation of vulnerabilities in Microsoft Exchange servers, including the ProxyLogon zero‑day flaws and other undisclosed Exchange weaknesses. Once inside, the actor deploys web shells—specifically variants of the China Chopper web shell—by modifying the ExternalUrl setting of the Exchange Offline Address Book to maintain remote command execution. To support credential harvesting, Hafnium uses batch files that dump LSASS memory, enabling the extraction of Windows domain credentials and the creation of user lists. The observed tooling consists primarily of these web shells and credential‑dumping utilities, with no public evidence of ransomware or cryptominer deployment in the incidents described. The actor’s approach emphasizes persistence via web shells even after server patching, indicating a focus on long‑term access rather than immediate destructive effects.
Representative operations attributed to Hafnium include the February 2022 compromise of the Association of Southeast Asian Nations’ mail servers, where valid credentials and Exchange exploits were used to exfiltrate gigabytes of emails affecting all member states. Another example is the March 2021 intrusion against Chile’s Comisión para el Mercado Financiero, in which ProxyLogon exploitation led to the installation of web shells and a credential‑dumping batch file, with the actor limiting activity to the Exchange platform and sharing indicators of compromise afterward. Additionally, Hafnium was linked to the March 2021 attack on the European Banking Authority’s Exchange servers, where zero‑day exploitation resulted in web shell deployment for remote access, although forensic review found no data exfiltration. These incidents illustrate the actor’s consistent reliance on Exchange vulnerabilities, web shell persistence, and credential harvesting to support espionage‑focused campaigns across multiple sectors and regions.
Incidents
Attributed incidents are available to members.
3 incidents