HAFNIUM__2021__Microsoft_New_nation-state_cyberattacks_03-02-2021.pdf
ID: 656579d7-a72b-45ac-bd66-b7900189f34e
STIX ID: report--656579d7-a72b-45ac-bd66-b7900189f34e
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2022-04-29
Last Modified Date: 2022-04-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Microsoft describes a nation-state threat actor named Hafnium that conducted targeted intrusions against U.S.-based organizations by exploiting previously unknown vulnerabilities in on-premises Exchange Server. The actor gained access via stolen credentials or zero-day vulnerabilities, deployed web shells for persistent remote control, and exfiltrated data; Microsoft released security updates and urged immediate patching while coordinating with government and security researchers.
