minidump_and_makecab_attacker is an intrusion cluster associated with exploitation of Microsoft Exchange Server vulnerabilities disclosed in 2021, including ProxyLogon-related flaws. The activity is characterized by post-compromise use of native Windows utilities for reconnaissance and credential theft. Observed tradecraft includes enumerating Active Directory users with dsquery.exe, dumping LSASS memory by invoking the Minidump function in comsvcs.dll through rundll32.exe, and compressing the resulting dump with makecab.exe for retrieval. This reflects a living-off-the-land approach focused on minimizing tooling requirements and blending into normal administrative activity. The cluster’s behavior aligns with broader Exchange exploitation waves in which multiple actors obtained high-privilege access to internet-facing Exchange servers, deployed webshells, conducted reconnaissance, stole credentials, and exfiltrated data. In this case, the distinguishing features are Active Directory enumeration and credential dumping via built-in Microsoft components rather than bespoke malware. Available information does not support a confident attribution to a specific named threat actor or country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.