LeakFang is a .NET backdoor associated with post-exploitation activity on compromised on-premises Microsoft SharePoint Server environments. It has been observed in intrusion activity following exploitation of SharePoint vulnerabilities, where attackers gain unauthorized access, steal IIS-protected secrets such as machine keys, and use those secrets to support continued access and persistence. Microsoft Defender identifies this activity as Backdoor:MSIL/LeakFang.A!dha.
The malware is linked to attacks against SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Its observed role is not initial compromise but follow-on malicious activity after server exploitation. Reported operator objectives in the surrounding intrusion set include harvesting IIS machine keys, enabling deserialization-based persistence, and deploying malware on affected servers. The responsible threat actors have not been publicly attributed to a named group.
LeakFang should be understood as part of a broader SharePoint post-compromise tradecraft cluster rather than a mass-distributed commodity threat. High-confidence reporting supports its use as a backdoor on Windows-based SharePoint servers and its association with theft of protected server secrets and persistence-related post-exploitation activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MDAV: Backdoor:MSIL/LeakFang.A!dha – post-exploitation activity alert involving IIS-protected secrets.
MDAV: Backdoor:MSIL/LeakFang.A!dha – post-exploitation activity alert involving IIS-protected secrets.
MDAV: Backdoor:MSIL/LeakFang.A!dha – post-exploitation activity alert involving IIS-protected secrets.
MDAV: Backdoor:MSIL/LeakFang.A!dha – post-exploitation activity alert involving IIS-protected secrets.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor detected by Microsoft Defender Antivirus in post-exploitation activity involving IIS-protected secrets during SharePoint exploitation.
A backdoor malware family referenced as a Defender detection to monitor for during SharePoint intrusion hunting.
A named backdoor detection associated with post-exploitation activity on SharePoint servers, specifically involving access to IIS-protected secrets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.