Attackers exploited unpatched on-premises Microsoft Exchange servers vulnerable to ProxyShell to gain initial access, deploy web shells and malicious .NET payloads, and abuse the compromised mail environment. In one intrusion, the Exchange server was used to send phishing replies from hijacked legitimate email threads to internal and external recipients, delivering DatopLoader followed by QBot; the activity then expanded into reconnaissance, persistence, command-and-control traffic, credential theft via registry hive dumping, and lateral movement with Cobalt Strike across the victim domain.
Separate analysis of ProxyShell post-exploitation found threat actors loading DLLs in memory from Exchange web processes, enumerating Exchange and Active Directory assets, testing domain controllers for Zerologon, extracting hashed credentials, and using pass-the-hash for persistence. One payload, Thor.dll, created domain accounts disguised as healthmailbox users and granted them the ApplicationImpersonation role, allowing covert access to and sending of email from any mailbox in the organization, underscoring how Exchange compromise can be turned into both malware delivery and long-term mailbox takeover.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Microsoft released KB5003435 to patch CVE-2021-31207, completing fixes for the three Exchange vulnerabilities known as ProxyShell.
Microsoft released KB5001779 to patch CVE-2021-34473 and CVE-2021-34523, two vulnerabilities later grouped as part of ProxyShell affecting on-premises Exchange Server.
The intrusion progressed to lateral movement across victim domains using Cobalt Strike Jump psexec and psexec_psh, while attackers also dumped SYSTEM, SECURITY, and SAM registry hives to obtain credentials.
After execution, QBot injected into explorer.exe, created scheduled-task persistence, contacted command-and-control servers, and performed host, network, and Active Directory reconnaissance using Adfind.exe and native Windows tools.
Victims who enabled macros in malicious Excel files triggered DatopLoader, which created the C:\Datop folder, downloaded DLL payloads, and executed them via regsvr32.exe, after which QBot took control of the host.
In a highlighted intrusion, attackers used the compromised Exchange server to send phishing emails as replies to legitimate stolen email threads, targeting internal and external recipients with DatopLoader-laced ZIP archives.
Cybereason investigated multiple 2021 compromises in which attackers exploited ProxyShell vulnerabilities on unpatched on-premises Microsoft Exchange servers for initial access.
FortiEDR detected suspicious activity when w3wp.exe injected into vbc.exe and loaded malicious DLLs in memory; Fortinet said protection mode blocked the malicious actions and prevented creation of domain accounts or further activity.
Using credentials obtained via Zerologon, Thor.dll created domain accounts masquerading as healthmailbox accounts and assigned them the Exchange ApplicationImpersonation role, enabling access to and sending of email from any mailbox in the organization.
In the FortiGuard-observed campaign, a DLL module probed specified domain controllers for Zerologon exposure and, when successful, returned usernames and hashed passwords before restoring the original computer hash.
FortiGuard Labs reported a separate ProxyShell campaign in which an unidentified actor used web shells on compromised Exchange servers to load 22 malicious .NET DLLs in memory for reconnaissance and follow-on actions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybereason.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.