44
Techniques
6
Toolsets
2
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About HAFNIUM

HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.

View MITRE record ↗

Techniques by Tactic (44)
Toolsets (6)
🐛
ASPXSpy S0073
Malware · Windows
🐛
Malware · Windows
🐛
Tarrask S1011
Malware · Windows
🔧
Covenant S1155
Tool · Linux, macOS, Windows
🔧
Impacket S0357
Tool · Linux, macOS, Windows
🔧
PsExec S0029
Tool · Windows
CVEs Referenced (2 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
↑