German authorities warned that the Chinese-linked espionage group APT27 was compromising commercial networks and maintaining access with the HyperBro remote access trojan, an in-memory backdoor used for persistence, remote administration, and data theft. The campaign was tied to exploitation of Microsoft Exchange ProxyLogon flaws, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065, as well as overlap with attacks abusing Zoho ManageEngine vulnerabilities. Officials said the intrusions could expand into supply-chain compromises affecting customers and service providers, and released indicators of compromise and YARA rules to help defenders detect HyperBro and related command-and-control activity.
Incident reports and threat research showed the Exchange compromises typically began with web shell deployment on exposed servers, followed by PowerShell-based reconnaissance, Active Directory enumeration, LSASS dumping, mailbox access, and attempts to package stolen data for exfiltration. In one detailed enterprise case attributed to APT27, the attackers moved laterally across multiple domains, escalated to domain administrator, extracted NTDS.DIT, staged data in password-protected RAR archives, and exfiltrated gigabytes of information through the Exchange server and HyperBro infrastructure while using DLL side-loading, masquerading, renamed tools, and Defender exclusions to evade detection. Researchers also warned that patching Exchange alone was not enough because many victims likely remained compromised through persistent web shells and other payloads.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
In 2022, a company found that one of its systems was communicating with a known command-and-control server and engaged CERT Intrinsec to investigate and manage incident response.
BfV said attackers started exploiting a Zoho ServiceDesk vulnerability on October 25, 2021. Palo Alto Networks researchers said related attacks compromised at least nine organizations in critical sectors worldwide.
According to BfV, attackers used a Zoho ADSelfService Plus zero-day exploit until mid-September 2021 before later switching to an n-day exploit.
The United States, European Union, United Kingdom, and NATO officially blamed China for the widespread Microsoft Exchange hacking campaign.
Unit 42 said the attacker successfully downloaded an archive containing dsquery results but repeatedly failed to download the LSASS dump archive, receiving HTTP 404 responses across multiple attempts. Cortex XDR protections on the server also prevented useful credential extraction from the dump.
Unit 42 observed the actor first access the installed Exchange webshell, run PowerShell for process enumeration, and automate follow-on activity from changing IP addresses. The attacker attempted Active Directory reconnaissance and LSASS memory dumping through batch scripts and cabinet archives.
Unit 42 reported that an unknown actor exploited multiple Exchange vulnerabilities to install a China Chopper-style webshell on a financial institution's Exchange server in the EMEA region. The webshell was saved as supp0rt.aspx under the IIS web root.
CERT Intrinsec said APT27 exploited a public-facing Microsoft Exchange server using the ProxyLogon chain, gaining remote code execution with SYSTEM privileges and beginning internal reconnaissance. This was identified as the first malicious activity in the intrusion.
BfV said APT27 exploited flaws in Zoho ADSelfService Plus beginning in March 2021 as part of campaigns using tactics and tooling similar to its other operations.
BfV said APT27 and other Chinese-backed groups were linked to exploitation of Microsoft Exchange ProxyLogon vulnerabilities in early March 2021, enabling takeover of unpatched Exchange servers and data theft worldwide.
Germany's BfV said the Chinese-linked threat group APT27 has been active since at least 2010 and is known for information theft and cyber-espionage.
CERT Intrinsec published an in-depth analysis attributing a 2021-2022 enterprise intrusion to APT27, detailing exploitation of ProxyLogon, deployment of HyperBro, credential theft, lateral movement, and exfiltration across four domains.
As part of its warning, BfV released indicators of compromise and YARA rules to help organizations detect HyperBro malware and APT27 command-and-control activity.
Germany's domestic intelligence agency BfV warned of an ongoing cyber-espionage campaign by APT27 targeting German commercial organizations. It said the attackers were using the HyperBro in-memory RAT to maintain persistence, steal sensitive information, and potentially expand into supply-chain attacks.
Cisco Talos reported that after Microsoft's initial disclosure, it observed shifts in tactics and incidents involving actors separate from Hafnium. Talos also noted heavy scanning and post-exploitation activity affecting sectors including financial services, healthcare, education, and government.
Microsoft disclosed several Microsoft Exchange Server zero-day vulnerabilities that were being actively exploited, initially attributing the activity to Hafnium. The disclosure prompted warnings that patching alone might not remove attacker persistence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
intrinsec.com
Open sourcebleepingcomputer.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.talosintelligence.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.