🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
HAFNIUM

/actor/hafnium/  ·  0 intel reports

Year Established
2021
Attribution
China (MSS)
Motivation
Espionage
Modus Operandi (MO)
Microsoft Exchange zero-day exploitation (ProxyLogon), web shell deployment, US defence contractor and NGO targeting
Primary Aliases
HAFNIUM, Bronze Compass (partial)

Hafnium is a Chinese state-sponsored threat actor attributed to the Ministry of State Security (MSS) that became the focus of international attention in March 2021 following the discovery that the group had been exploiting four critical zero-day vulnerabilities in Microsoft Exchange Server , collectively designated ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) , to compromise tens of thousands of Exchange servers globally.

The ProxyLogon vulnerability chain allowed Hafnium to bypass authentication and execute arbitrary code on Exchange servers without valid credentials, effectively providing remote access to any vulnerable internet-exposed Exchange installation. Microsoft's emergency out-of-band patch release in March 2021 triggered a race condition as Hafnium and other threat actors scrambled to exploit unpatched servers before administrators could apply fixes , resulting in mass exploitation events affecting organisations in virtually every sector globally.

Hafnium's primary targeting focus includes US-based defence contractors, law firms, infectious disease researchers, NGOs, think tanks, and higher education institutions , all categories of organisations holding intelligence of significant value to Chinese strategic interests. The group extracts email communications and internal documents to inform Chinese state decision-making on foreign policy, defence technology, and scientific research.

The scale of the ProxyLogon exploitation , which affected an estimated 250,000 servers globally before patches were applied , prompted the White House to publicly attribute the campaign to China with an unprecedented level of international coordination, with the UK, EU, NATO, and dozens of allied nations simultaneously issuing attribution statements. The incident remains one of the most consequential mass-exploitation events in cybersecurity history.

Cyber Espionage Tactics and Persistence Mechanisms: Operational tracking indicates that Hafnium executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles