logo

HAFNIUM__2021__Microsoft_New_nation-state_cyberattacks_03-02-2021.pdf

ID: 656579d7-a72b-45ac-bd66-b7900189f34e

STIX ID: report--656579d7-a72b-45ac-bd66-b7900189f34e

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2022-04-29

Last Modified Date: 2022-04-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Microsoft describes a nation-state threat actor named Hafnium that conducted targeted intrusions against U.S.-based organizations by exploiting previously unknown vulnerabilities in on-premises Exchange Server. The actor gained access via stolen credentials or zero-day vulnerabilities, deployed web shells for persistent remote control, and exfiltrated data; Microsoft released security updates and urged immediate patching while coordinating with government and security researchers.