APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
HAFNIUM (aka Silk Typhoon, DEV-0322) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
HAFNIUM
G0125
APT
CN · China
AKA
Silk Typhoon · DEV-0322 · Operation Exchange Marauder
CrowdStrike
:
JUDGMENT PANDA
Mandiant
:
UNC3944
MITRE
:
G0125
Secureworks
:
IRON TYPHOON
PRC cluster behind the 2021 Microsoft Exchange ProxyLogon mass exploitation.
Targets
2
Sectors
10
Threat types
1
GIRs covered
0/480
Active since
2017
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 3 other aliases
Open Rosetta Stone
CrowdStrike
JUDGMENT PANDA
Mandiant
UNC3944
Microsoft
HAFNIUM
MITRE
G0125
Secureworks
IRON TYPHOON
UNATTRIBUTED ALIASES
Silk Typhoon
DEV-0322
Operation Exchange Marauder
Victimology
Geographic footprint · 2 countries
Region filter
Export
origin · China
targeted countries · 2
ASIA ·
1
United Arab Emirates
AMERICAS ·
1
United States
Sectors targeted
10 of 40
Government
100 actors
Defense
72 actors
Financial Services
74 actors
Healthcare
47 actors
Technology
60 actors
Telecom
72 actors
Education & Research
62 actors
Legal & Professional
18 actors
Consulting / Professional Services
35 actors
Industrials / Engineering
29 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 33 techniques
Reconnaissance
· 3
T1589.002
Email Addresses
T1590
Gather Victim Network Information
T1592.004
Client Configurations
Resource Development
· 3
T1583.003
Virtual Private Server
T1583.005
Botnet
Initial Access
· 2
T1190
Exploit Public-Facing Application
Execution
· 2
T1059.001
PowerShell
T1059.003
Persistence
· 1
T1098
Account Manipulation
Privilege Escalation
· 1
T1068
Exploitation for Privilege Escalation
Credential Access
· 3
T1003.001
LSASS Memory
Discovery
· 5
T1016
System Network Configuration Discovery
Lateral Movement
· 1
Collection
· 4
T1005
Data from Local System
T1114.002
Remote Email Collection
T1119
Automated Collection
Exfiltration
· 1
T1567.002
Exfiltration to Cloud Storage
Command And Control
· 3
T1071.001
Web Protocols
T1095
Non-Application Layer Protocol
Stealth
· 4
T1078.003
Local Accounts
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
33 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1583.006
Web Services
T1199
Trusted Relationship
Windows Command Shell
T1003.003
NTDS
T1555.006
Cloud Secrets Management Stores
T1018
Remote System Discovery
T1033
System Owner/User Discovery
T1057
Process Discovery
T1083
File and Directory Discovery
T1550.001
Application Access Token
T1560.001
Archive via Utility
T1105
Ingress Tool Transfer
T1078.004
Cloud Accounts
T1218.011
Rundll32
T1564.001
Hidden Files and Directories