Attackers actively exploited the ProxyShell chain in unpatched on-premises Microsoft Exchange servers to gain remote code execution, plant web shells, and establish persistent access, with incidents linked to LockFile ransomware deployment. The intrusion path combined CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 to bypass authentication, escalate privileges, and execute code through exposed Exchange services, while broad internet scanning targeted Exchange Client Access Service instances over IIS. Reporting also warned that applying Exchange updates blocks new exploitation but does not remove web shells or other attacker footholds already left behind on compromised servers.
Post-compromise activity included PowerShell-based payload delivery, Cobalt Strike deployment, privilege escalation, and in some cases abuse of PetitPotam (CVE-2021-36942) for NTLM relay and deeper domain compromise. Researchers described attackers using Exchange web shells, suspicious .aspx files, w3wp.exe child processes, mailbox export abuse, scheduled tasks, and Active Directory Group Policy plus the NETLOGON share to spread ransomware across enterprise environments, turning an initial Exchange breach into domain-wide encryption.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
Microsoft's Exchange team published a warning urging users to apply the relevant patches quickly in response to ongoing ProxyShell exploitation.
By August 23, 2021, attackers including the LockFile ransomware group were exploiting ProxyShell and PetitPotam against enterprise environments, leading to ransomware deployment and host encryption.
Sophos reported that LockFile uses intermittent encryption, encrypting every alternate 16 bytes of a file to evade ransomware defenses based on statistical analysis. The analysis also described related behavior including WMI-based process termination, a LockBit-like ransom note, and self-deletion after encryption.
Public exploit code for ProxyShell became available on GitHub and Reddit, lowering the barrier to exploitation of unpatched Exchange servers.
An independent security researcher captured activity involving IP address 209.14.0[.]234 on August 13, 2021, which the report says was used to exploit ProxyShell vulnerabilities. The infrastructure was also linked to PowerShell retrieval activity observed during LockFile intrusions.
Microsoft's August 11, 2021 security updates included a patch for the PetitPotam-related Windows LSA spoofing vulnerability tracked as CVE-2021-36942.
A Taiwan security researcher presented details of the Exchange vulnerability chain at Black Hat USA 2021 and named the chain ProxyShell.
Microsoft released advisory ADV210003 warning about an NTLM relay attack related to Active Directory Certificate Services and the PetitPotam technique.
Symantec said the LockFile ransomware campaign was first observed on July 20, 2021, on the network of a U.S. financial organization. The attackers were assessed to have compromised Microsoft Exchange and later used PetitPotam to reach the domain controller before deploying ransomware.
A French researcher released proof-of-concept code for PetitPotam, enabling broader testing and abuse of the NTLM relay technique tied to CVE-2021-36942.
Microsoft's July 14, 2021 security updates included bulletins covering CVE-2021-34473 and CVE-2021-31207, drawing further attention to the Exchange flaws.
Microsoft disclosed additional Exchange vulnerabilities in its July 2021 security updates, including bulletins for CVE-2021-34473 and CVE-2021-31207.
Microsoft released KB5003435 in May 2021 to fix CVE-2021-31207, the arbitrary file write flaw used for remote code execution in the ProxyShell attack chain.
Microsoft released KB5001779 in April 2021 to fix CVE-2021-34473 and CVE-2021-34523, two of the Exchange vulnerabilities later used in the ProxyShell chain.
A security researcher reported multiple Microsoft Exchange Server vulnerabilities to Microsoft, beginning the disclosure process for the flaws later chained as ProxyShell.
Sophos said threat actors were actively scanning for and exploiting vulnerable on-premises Exchange servers and noted that LockFile appeared to be using ProxyShell against unpatched targets.
The Metasploit Framework was updated with exploits for the ProxyShell vulnerabilities, further operationalizing public exploitation.
Microsoft published KB5005413 with mitigation guidance for NTLM relay attacks involving PetitPotam against Active Directory Certificate Services. The guidance recommends enabling Extended Protection for Authentication, requiring HTTPS on AD CS web services, and restricting or disabling NTLM where possible.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcenews.sophos.com
Open sourcensfocusglobal.com
Open sourcecsoonline.com
Open sourcemsrc.microsoft.com
Open sourcesupport.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.