Netskope Threat Labs

SharpHafnium

ATP Sandbox Adv. HeuristicsAV

SharpHafnium is a tool that exposes the exploitation techniques of the Hafnium threat group, which Microsoft attributed to a Chinese state sponsored actor targeting Microsoft Exchange servers in early 2021. The underlying attacks abused server side request forgery and deserialization vulnerabilities to steal messages and deploy web shells on exposed Exchange hosts.

First seen
February 2022
Last seen
October 2026
Alert Name
Dump:Generic.SharpHafnium.B.FFFFFFFE
Generic.SharpHafnium.A.01646834
Generic.SharpHafnium.A.44E4987A
Generic.SharpHafnium.A.541F4D40
Generic.SharpHafnium.A.8E8B4ACF
Generic.SharpHafnium.A.AC5780AF
Generic.SharpHafnium.B.0284F03A
Generic.SharpHafnium.B.05CF82A8
Generic.SharpHafnium.B.0EF3C15F
Generic.SharpHafnium.B.108CBA44