Hafnium (aka Silk Typhoon / MURKY PANDA) is a China-linked APT that conducts global cyber espionage against governments, research, and critical infrastructure using exploits (including CVE-2020-0688 and CVE-2021-26855), cloud credential abuse, supply-chain tactics, and a multi-tier contracting model of private firms. Recent campaigns show SharePoint exploitation, SEO poisoning, IoT and supply-chain targeting, and deployment of tools/malware such as Covenant, China Chopper, Tarrask, PlugX, and Whitebird. #Hafnium #CVE-2020-0688 #CVE-2021-26855 #Tarrask #PlugX #Whitebird
Keypoints
- Hafnium is a state-sponsored Chinese APT (also known as Silk Typhoon / MURKY PANDA) focused on espionage against defense, higher education, medical research, and supply-chain-dependent industries.
- The group leverages zero-day and public-facing application exploits, notably CVE-2020-0688 and CVE-2021-26855, to compromise SharePoint, email servers, and other enterprise products.
- Hafnium employs a multi-tier contracting model, using nominally private Chinese firms and third-party service providers to develop and operate offensive tooling.
- Recent campaigns emphasize cloud abuse (compromised credentials, cloud instance lateral movement), SEO poisoning to distribute malware, and attempts to compromise IoT and supply-chain infrastructure.
- Tools and frameworks observed include Covenant, Impacket, PsExec, Nishang, PowerCat, China Chopper, ASPXSpy, and archive utilities for collection/exfiltration.
- Malware families associated with Hafnium include Tarrask, PlugX, and Whitebird, used for persistence, remote access, and data theft.
- Operations exhibit advanced forensic and data collection capabilities, including encrypted data acquisition and remote access to mobile/Apple devices and physically secured endpoints.
MITRE Techniques
- [T1589.002 ] Gather Victim Identity Information: Email Addresses β Used during reconnaissance to collect targeted email addresses for follow-on access or phishing.
- [T1592.004 ] Gather Victim Host Information: Client Configurations β Hafnium gathers client configuration details to tailor exploitation and post-compromise actions.
- [T1590 ] Gather Victim Network Information β The group maps victim networks to identify targets and lateral movement paths.
- [T1590.005 ] Gather Victim Network Information: IP Addresses β Collection of IP addresses to enumerate and target networked systems.
- [T1593.003 ] Search Open Websites/Domains: Code Repositories β Searching public code repositories to gather intelligence or discover credentials/configurations.
- [T1583.003 ] Acquire Infrastructure: Virtual Private Server β Use of VPS infrastructure to host tooling and C2 services.
- [T1583.005 ] Acquire Infrastructure: Botnet β Utilization or purchase of botnet resources as part of infrastructure acquisition.
- [T1583.006 ] Acquire Infrastructure: Web Services β Use of third-party web services to support operations and hosting.
- [T1584.005 ] Compromise Infrastructure: Botnet β Compromising external infrastructure such as botnets to amplify capabilities.
- [T1199 ] Trusted Relationship β Leveraging trusted relationships (e.g., supply chain partners) for initial access.
- [T1190 ] Exploit Public-Facing Application β Exploitation of SharePoint and other public-facing apps, including CVE-2020-0688 and CVE-2021-26855.
- [T1078.003 ] Valid Accounts: Local Accounts β Use and creation of local valid accounts for access and persistence.
- [T1078.004 ] Valid Accounts: Cloud Accounts β Use of compromised cloud accounts to access cloud resources and move laterally.
- [T1059.001 ] Command and Scripting Interpreter: PowerShell β Execution of PowerShell scripts (e.g., Nishang, PowerCat) for command execution and payload delivery.
- [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell β Use of Windows shell commands and tools (e.g., PsExec) for execution and lateral movement.
- [T1136.002 ] Create Account: Domain Account β Creation of domain accounts to maintain persistence and elevate access.
- [T1098 ] Account Manipulation β Manipulation of accounts to maintain access and escalate privileges.
- [T1505.003 ] Server Software Component: Web Shell β Deployment of web shells such as ASPXSpy or China Chopper for persistence on web servers (βASPXSpyβ, βChina Chopperβ).
- [T1068 ] Exploitation for Privilege Escalation β Exploiting vulnerabilities to gain higher privileges on hosts.
- [T1564.001 ] Hide Artifacts: Hidden Files and Directories β Hiding files/directories to evade detection.
- [T1070.001 ] Indicator Removal: Clear Windows Event Logs β Clearing Windows event logs to remove traces of activity.
- [T1218.011 ] System Binary Proxy Execution: Rundll32 β Using system binaries like rundll32 to proxy execution and evade controls.
- [T1550.001 ] Use Alternate Authentication Material: Application Access Token β Abuse of application access tokens and alternate auth material for lateral movement.
- [T1110.003 ] Brute Force: Password Spraying β Credential-stuffing and password-spraying against accounts to gain access.
- [T1555.006 ] Credentials from Password Stores: Cloud Secrets Management Stores β Harvesting credentials from cloud secret stores for access to cloud resources.
- [T1003.001 ] OS Credential Dumping: LSASS Memory β Dumping LSASS memory to extract credentials.
- [T1003.003 ] OS Credential Dumping: NTDS β Dumping NTDS to obtain domain credentials.
- [T1083 ] File and Directory Discovery β Enumerating files and directories to locate sensitive data.
- [T1057 ] Process Discovery β Enumerating running processes to identify defensive or targeted applications.
- [T1018 ] Remote System Discovery β Discovering remote systems for lateral movement opportunities.
- [T1016 ] System Network Configuration Discovery β Mapping system network configuration to plan operations.
- [T1016.001 ] System Network Configuration Discovery: Internet Connection Discovery β Determining internet-facing connections and configurations.
- [T1033 ] System Owner/User Discovery β Identifying system owners and users for targeted collection.
- [T1560.001 ] Archive Collected Data: Archive via Utility β Using archive utilities to compress and prepare data for exfiltration.
- [T1119 ] Automated Collection β Automated collection of files/data for efficiency and scale.
- [T1530 ] Data from Cloud Storage β Collecting sensitive data from cloud storage services.
- [T1213.002 ] Data from Information Repositories: SharePoint β Targeting SharePoint repositories to collect and exfiltrate data (βexploited a security flaw in SharePoint, affecting thousands of serversβ).
- [T1005 ] Data from Local System β Collecting files from local systems for exfiltration.
- [T1114.002 ] Email Collection: Remote Email Collection β Remote collection of email content from compromised mail systems.
- [T1071.001 ] Application Layer Protocol: Web Protocols β C2 over web protocols for command and control and data transfer.
- [T1132.001 ] Data Encoding: Standard Encoding β Use of standard encoding methods to obfuscate C2 or payload data.
- [T1105 ] Ingress Tool Transfer β Transferring tools into victim environments (ingress of tooling like Covenant, China Chopper).
- [T1095 ] Non-Application Layer Protocol β Use of non-application layer protocols where applicable for C2 or data transfer.
- [T1567.002 ] Exfiltration Over Web Service: Exfiltration to Cloud Storage β Exfiltrating collected data to cloud storage services as a destination.
Indicators of Compromise
- [Malware ] observed tool/malware names β Tarrask, PlugX, Whitebird (associated with persistence and remote access).
- [Tooling ] common tools and web shells β Covenant, China Chopper, ASPXSpy, PowerCat (used for C2, web shell access, and command execution).
- [Vulnerabilities ] exploited CVEs β CVE-2020-0688, CVE-2021-26855 (SharePoint and email server exploitation context).
- [Targets / Technologies ] targeted platforms β Microsoft SharePoint, Citrix Netscaler, Commvault Web Server, cloud infrastructure (examples of targeted systems and services).
- [TTP Context ] credential and cloud artifacts β compromised cloud accounts and application access tokens observed (credentials from cloud secrets stores and password spraying attempts).
Read more: https://www.cyfirma.com/research/apt-profile-hafnium/