Attackers exploited two Microsoft Exchange zero-days, CVE-2022-41040 and CVE-2022-41082, in a campaign discovered by GTSC during an August 2022 investigation into an attack on critical infrastructure. GTSC disclosed the vulnerabilities on September 29, 2022, and Microsoft confirmed active exploitation. Known as ProxyNotShell, the flaws affect on-premises Exchange deployments and allow an authenticated attacker to chain server-side request forgery with remote code execution.
SecurityScorecard identified more than 48,000 Exchange assets and examined possible webshell infections and communications associated with published indicators of compromise. Network-flow analysis revealed potentially relevant remote PowerShell traffic and large transfers involving a reported command-and-control server, but did not establish exploitation or data exfiltration; the asset count likewise did not represent confirmed infections. At the investigation’s September 30, 2022 cutoff, no patch was available. The report recommended checking for compromise, deploying Microsoft’s detections, and restricting public access to Exchange and remote PowerShell services.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
SecurityScorecard's Attack Surface Intelligence identified more than 48,000 assets running Exchange servers as of September 30. Identification alone did not establish that those servers were vulnerable or compromised.
GTSC disclosed CVE-2022-41040 and CVE-2022-41082 following its investigation of active exploitation. The flaws affect on-premises Exchange and allow an authenticated attacker to chain server-side request forgery with remote code execution.
SecurityScorecard recorded another transfer of a reported 4.5 MB from 104.90.25.126 to 185.220.101.182 over port 5986. Traffic involving the indicator could not automatically be attributed to the Exchange vulnerabilities.
SecurityScorecard observed 69.55.53.168 transferring 12.29 MB to 185.220.101.182 over port 5986. Researchers attributed the source address to ServerStack but did not establish that the transfer represented Exchange exploitation.
SecurityScorecard observed 104.90.25.126 transferring a reported 4.5 MB to 185.220.101.182 over port 5986. The source address belonged to shared Akamai infrastructure in Belgium, and the observation did not establish compromise of its associated organizations.
SecurityScorecard observed 86.48.12.64 sending 126 bytes to port 5985 on 160.238.137.146, which returned 330 bytes that day. The traffic did not establish exploitation of the Exchange vulnerabilities.
GTSC first observed exploitation of previously unknown Microsoft Exchange vulnerabilities while investigating an attack against critical infrastructure. The flaws were subsequently identified as CVE-2022-41040 and CVE-2022-41082.
SecurityScorecard's investigation identified potentially compromised entities, including US educational institutions, and 40 HTTPS flows of at least 100 MB involving the reported command-and-control address and 22 counterpart addresses. Researchers cautioned that webshell-path results included false positives and that the transfers did not conclusively demonstrate targeting or exfiltration.
GTSC published 17 exploitation-associated IP indicators and identified 137.184.67.33 as a command-and-control address specifically associated with exploitation of the Exchange vulnerabilities.
Microsoft confirmed active exploitation of CVE-2022-41040 and CVE-2022-41082, with evidence of limited, targeted attacks against on-premises Exchange deployments.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.