HAFNIUM
MITRE G0049Also known as Hafnium, Silk Typhoon
Reports
3
First seen
Mar 3, 2021
Last seen
Aug 10, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
United States ×1
Top ATT&CK techniques
T1190 Exploit Public-Facing Application ×4T1547.005 Startup Folder ×1T1001 Data Obfuscation ×1T1105 Ingress Tool Transfer ×1T1053.005 Scheduled Task ×1T1003 OS Credential Dumping ×1T1140 Deobfuscate/Decode Files or Information ×1T1059.001 PowerShell ×1T1036 Masquerading ×1T1505 Server Software Component ×1T1505.003 Web Shell ×1
Indicators
hash_sha256 ×5domain ×4filename ×2registry_key ×2hash_md5 ×1cve ×1ip_v4 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
Critical