HAFNIUM__2021__HAFNIUM_targeting_Exchange_Servers_with_0-day_exploits_-_Microsoft_Security.pdf
ID: 738f3c4a-c389-4f45-a6d4-b3941a242b6b
STIX ID: report--738f3c4a-c389-4f45-a6d4-b3941a242b6b
Threat Score
92/100
Uploaded: 2026-08-15
Published Date: 2021-03-12
Last Modified Date: 2021-03-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Microsoft reports that the HAFNIUM group exploited multiple zero-day vulnerabilities in on-premises Exchange Server to gain unauthorized access, deploy web shells, dump LSASS memory, export mailbox data, and exfiltrate information; the advisory lists exploited CVEs, example web shell and post-exploitation commands, observable IOCs (file hashes, paths, filenames), and detection/hunting queries and mitigations, urging immediate patching and investigation.
