https://blogs.microsoft.com/on-the-issues/2021/03/02/new-nation-state-cyberattacks/ Skip to content Skip to main content [RE1Mu3b] Microsoft Microsoft On the Issues Microsoft On the Issues Microsoft On the Issues * Home * The Official Microsoft Blog * The AI Blog * Transform * More * All Microsoft + o Microsoft 365 o Office o Windows o Surface o Xbox o Deals o Support + Software o Windows Apps o OneDrive o Outlook o Skype o OneNote o Microsoft Teams o Microsoft Edge + PCs & Devices o Computers o Shop Xbox o Accessories o VR & mixed reality o Phones + Entertainment o Xbox Game Pass Ultimate o Xbox Live Gold o Xbox games o PC games o Windows digital games o Movies & TV + Business o Microsoft Azure o Microsoft Dynamics 365 o Microsoft 365 o Microsoft Industry o Data platform o Microsoft Advertising o Power Platform o Shop Business + Developer & IT o .NET o Visual Studio o Windows Server o Windows Dev Center o Docs o Power Apps o HoloLens 2 + Other o Microsoft Rewards o Free downloads & security o Education o Virtual workshops and training o Gift cards o Licensing o Microsoft Experience Center + View Sitemap [ ] Search Cancel 0 Cart 0 items in shopping cart New nation-state cyberattacks Mar 2, 2021 | Tom Burt - Corporate Vice President, Customer Security & Trust * Share on Facebook (opens new window) * Share on LinkedIn (opens new window) * Share on Twitter (opens new window) Graphic representation of a lock Today, we're sharing information about a state-sponsored threat actor identified by the Microsoft Threat Intelligence Center (MSTIC) that we are calling Hafnium. Hafnium operates from China, and this is the first time we're discussing its activity. It is a highly skilled and sophisticated actor. Historically, Hafnium primarily targets entities in the United States for the purpose of exfiltrating information from a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks and NGOs. While Hafnium is based in China, it conducts its operations primarily from leased virtual private servers (VPS) in the United States. Recently, Hafnium has engaged in a number of attacks using previously unknown exploits targeting on-premises Exchange Server software. To date, Hafnium is the primary actor we've seen use these exploits, which are discussed in detail by MSTIC here. The attacks included three steps. First, it would gain access to an Exchange Server either with stolen passwords or by using the previously undiscovered vulnerabilities to disguise itself as someone who should have access. Second, it would create what's called a web shell to control the compromised server remotely. Third, it would use that remote access - run from the U.S.-based private servers - to steal data from an organization's network. We're focused on protecting customers from the exploits used to carry out these attacks. Today, we released security updates that will protect customers running Exchange Server. We strongly encourage all Exchange Server customers to apply these updates immediately. Exchange Server is primarily used by business customers, and we have no evidence that Hafnium's activities targeted individual consumers or that these exploits impact other Microsoft products. Even though we've worked quickly to deploy an update for the Hafnium exploits, we know that many nation-state actors and criminal groups will move quickly to take advantage of any unpatched systems. Promptly applying today's patches is the best protection against this attack. In addition to offering new protections for our customers, we've briefed appropriate U.S. government agencies on this activity. This is the eighth time in the past 12 months that Microsoft has publicly disclosed nation-state groups targeting institutions critical to civil society; other activity we disclosed has targeted healthcare organizations fighting Covid-19, political campaigns and others involved in the 2020 elections, and high-profile attendees of major policymaking conferences. We are encouraged that many organizations are voluntarily sharing data with the world, among each other and with government institutions committed to defense. We're grateful to researchers at Volexity and Dubex who notified us about aspects of this new Hafnium activity and worked with us to address it in a responsible way. We need more information to be shared rapidly about cyberattacks to enable all of us to better defend against them. That is why Microsoft President Brad Smith recently told the U.S. Congress that we must take steps to require reporting of cyber incidents. The exploits we're discussing today were in no way connected to the separate SolarWinds-related attacks. We continue to see no evidence that the actor behind SolarWinds discovered or exploited any vulnerability in Microsoft products and services. Related Stories Sep 10, 2020 | Tom Burt New cyberattacks targeting U.S. elections Oct 28, 2020 | Tom Burt Cyberattacks target international conference attendees Dec 30, 2019 | Tom Burt Microsoft takes court action against fourth nation-state cybercrime group Sep 29, 2020 | Tom Burt Microsoft report shows increasing sophistication of cyber threats Stay Connected Have the latest posts sent right to your inbox. Enter your email below. By providing your email address, you will receive email updates from the Microsoft on the Issues blog. Email Address [ ] [Subscribe] Follow us: * Check us out on RSS What's new * Surface Duo * Surface Laptop Go * Surface Pro X * Surface Go 2 * Surface Book 3 * Microsoft 365 * Windows 10 apps * HoloLens 2 Microsoft Store * Account profile * Download Center * Microsoft Store support * Returns * Order tracking * Virtual workshops and training * Microsoft Store Promise * Financing Education * Microsoft in education * Office for students * Office 365 for schools * Deals for students & parents * Microsoft Azure in education Enterprise * Azure * AppSource * Automotive * Government * Healthcare * Manufacturing * Financial services * Retail Developer * Microsoft Visual Studio * Windows Dev Center * Developer Center * Microsoft developer program * Channel 9 * Office Dev Center * Microsoft Garage Company * Careers * About Microsoft * Company news * Privacy at Microsoft * Investors * Diversity and inclusion * Accessibility * Security English (United States) * Contact us * Privacy * Manage cookies * Terms of use * Trademarks * About our ads * (c) Microsoft 2021