Mikroceen, also known as Vicious Panda, is a China-associated advanced persistent threat group that typically targets organizations in Central Asia. Its documented victims include a utility company in that region. In March 2021, the group exploited the ProxyLogon vulnerabilities in an on-premises Microsoft Exchange Server at the utility company, compromising the server one day after Microsoft released patches. The ProxyLogon vulnerability chain enables unauthenticated remote code execution. Mikroceen's follow-on activity included injecting versions of Mimikatz, a tool used to extract credentials from compromised Windows systems. This activity demonstrates exploitation of internet-facing infrastructure for initial access and credential-theft tooling during post-exploitation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several actors associated in the content with attacks involving HawkEye.
Compromised a Central Asian utility company's Exchange server after patch release. The article identifies Central Asia as its principal targeting region.
Post-patch exploitation of Exchange vulnerabilities against a Central Asian utility; deployed Mimikatz variants for credential theft.
Compromised a utility company's Exchange server in Central Asia as part of the ProxyLogon exploitation activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.