HAFNIUM
1 incidentes
1 paises
1 sectores
apt CN Ultimo: 2026-05-25
Aliases: Hade ransomware, TimosaraHackerTerm
HAFNIUM is a state-sponsored cyber espionage group, assessed with high confidence to operate out of China and linked to its Ministry of State Security. The group emerged with notable activity as early as December 2020, becoming widely known in early 2021 for its exploitation of zero-day vulnerabilities in Microsoft Exchange Server. HAFNIUM distinguishes itself by its speed in operationalizing newly discovered vulnerabilities in internet-facing infrastructure and often employs a multi-tier contracting model, utilizing nominally private Chinese firms to conduct its operations. While primarily targeting entities in the United States, its operations extend globally. The group is also known by the aliases Silk Typhoon, Operation Exchange Marauder, Murky Panda, Red Dev 13, and G0125, and has connections to APT40.