Microsoft Exposes Chinese Hafnium Group Exploiting Exchange Servers
Microsoft reveals details about a Chinese state-sponsored hacking group named Hafnium that actively targets US organizations using undisclosed vulnerabilities in Exchange Server software. The company urges all business customers to apply immediate security patches to prevent data theft.
Microsoft shares details about a highly sophisticated state-sponsored threat actor from China known as Hafnium. This group primarily targets US organizations across various sectors, including infectious disease research, law firms, higher education, defense, and NGOs, with the goal of stealing sensitive information.
Hafnium executes its attacks through a precise three-step process targeting on-premises Exchange Server software. The hackers first gain access using stolen passwords or undiscovered vulnerabilities, then install a web shell for remote control, and finally use leased US-based servers to exfiltrate data from the compromised networks.
Microsoft releases critical security updates to protect Exchange Server customers from these specific exploits and strongly advises immediate installation. Because other threat actors quickly adopt unpatched system vulnerabilities, applying these updates remains the most effective defense against this ongoing campaign.