six_character_webshell_attacker is an uncategorized intrusion actor observed during the mass exploitation of Microsoft Exchange Server vulnerabilities disclosed in 2021, including ProxyLogon-related flaws such as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. The actor was seen uploading webshells to compromised Exchange servers and copying them to additional locations within the webroot, indicating efforts to preserve access and improve operational resilience after initial compromise. Activity associated with this intrusion cluster fits a broader pattern of Exchange exploitation in which attackers obtained remote code execution and elevated privileges on internet-facing mail servers, then used webshell-based access for follow-on operations. High-confidence behaviors supported here include initial access through exploitation of public-facing applications, persistence through webshell deployment and duplication, and post-exploitation actions consistent with hands-on-keyboard server abuse. The available evidence does not support a reliable attribution to a named nation-state or criminal group, nor does it establish a distinct malware family beyond generic webshell usage. This actor should be understood as a practical post-exploitation operator leveraging exposed Exchange infrastructure for durable access rather than as a fully attributed threat group with a well-established alias set. No high-confidence evidence here supports ransomware deployment, extortion operations, or a specific geographic origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.