An intrusion set observed during the mass exploitation of Microsoft Exchange Server vulnerabilities disclosed in 2021. This activity involved creating virtual directories within the Exchange webroot using native Microsoft administration tooling and then clearing Windows event logs with built-in utilities to reduce forensic visibility. The broader intrusion pattern associated with this cluster included exploitation of Exchange vulnerabilities such as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 to obtain high-privilege access on internet-facing servers, followed by deployment of webshells for persistent remote command execution. Related post-exploitation behavior seen in the same campaign ecosystem included credential dumping, reconnaissance of Active Directory and host environments, ingress of additional tools, file hiding and cleanup, and data theft. The tradecraft relied heavily on living-off-the-land techniques and native Windows utilities for defense evasion and post-compromise operations. Attribution to a specific named threat actor is not currently available from the supplied facts, and this activity should be treated as a distinct, behaviorally defined attacker cluster rather than a confidently attributed group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.