Microsoft warned in October 2020 that Iranian nation-state actor MERCURY, also known as MuddyWater, Static Kitten and Seedworm, had actively exploited Zerologon (CVE-2020-1472) during the preceding two weeks. The critical flaw in Microsoft’s Netlogon Remote Protocol allows an unauthenticated attacker with network access to a domain controller to obtain domain administrator privileges and compromise Active Directory identity services. Microsoft did not identify MERCURY’s victims. A separate Microsoft analysis described an attack chain combining a SharePoint vulnerability, a web shell and Cobalt Strike with Zerologon attacks against domain controllers; it did not establish that this chain belonged to MERCURY.
Microsoft released initial fixes on August 11, 2020, but public exploit releases in September increased the risk and prompted an emergency federal patching directive. Remediation followed a two-phase rollout, with Netlogon secure-channel enforcement enabled by default in February 2021. Zerologon subsequently became a tool for nation-state actors and ransomware operators and entered known-exploited vulnerability tracking. Defenders should verify that domain controllers are fully patched, confirm secure-channel enforcement and address incompatible Netlogon connections rather than relying solely on the initial update.

See which actors are running it and whether you're in range.
20 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced that it had observed MERCURY, also known as MuddyWater, Static Kitten and Seedworm, exploiting CVE-2020-1472 in active campaigns during the preceding two weeks. Microsoft did not disclose the victims.
Microsoft's activity graph showed Zerologon exploitation attempts by attackers and red teams beginning as early as September 13 and continuing thereafter.
Four proof-of-concept exploits for Zerologon were released publicly on GitHub, increasing the risk to unpatched Windows domain controllers.
MITRE and NVD metadata identify August 17, 2020, as the publication date for CVE-2020-1472, a critical Netlogon vulnerability that can allow unauthenticated attackers to obtain domain administrator access.
Microsoft released patches for CVE-2020-1472 in its August 11 Patch Tuesday updates, beginning a phased rollout to change how Windows handles Netlogon secure channels.
Fedora published package security announcements concerning CVE-2020-1472.
Ubuntu published security notices USN-4559-1, USN-4510-2 and USN-4510-1 addressing CVE-2020-1472.
Synology published security advisory Synology_SA_20_21 concerning CVE-2020-1472.
CERT/CC published vulnerability note VU#490028 for CVE-2020-1472.
Microsoft published guidance titled “How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472” to support its phased remediation rollout.
U.S. government agencies issued a joint cybersecurity advisory warning that advanced threat groups were chaining vulnerabilities to enter government networks and elevate privileges.
Microsoft described an attacker exploiting SharePoint flaw CVE-2019-0604, installing a web shell and deploying a Cobalt Strike-based payload before targeting domain controllers with Zerologon. The analysis did not explicitly attribute this attack chain to MERCURY.
Cisco Talos researchers warned of increased Zerologon exploitation attempts approximately one week before Microsoft's MERCURY alert.
Following public exploit releases, CISA issued Emergency Directive 20-04 requiring federal agencies to patch affected Windows Servers by September 21, 2020. The references do not specify the directive's issuance date.
Oracle's April 2021 Critical Patch Update included coverage for CVE-2020-1472. The overall update addressed 257 CVEs with 390 patches.
Microsoft released an additional Zerologon patch that enabled a protective security setting by default, implementing the second phase of its remediation rollout.
Debian LTS published an advisory addressing CVE-2020-1472.
The Samba Team released security versions 4.10.18, 4.11.13, and 4.12.7 and patches addressing CVE-2020-1472. The updates add server-side checks on client-supplied Netlogon challenges to mitigate the attack.
The Samba Team published an advisory confirming that certain Samba versions configured as domain controllers are vulnerable to CVE-2020-1472, extending the disclosed scope of Zerologon beyond Windows domain controllers.
openSUSE published security announcements addressing CVE-2020-1472.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
threatpost.com
Open sourcecyber.gc.ca
Open sourcetenable.com
Open sourcesamba.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.