malicious_dll_attacker is an intrusion activity cluster associated with post-exploitation of Microsoft Exchange Server vulnerabilities disclosed in 2021, including ProxyLogon-related flaws such as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. The activity reflects an opportunistic server-compromise operator rather than a clearly attributed nation-state or formally tracked group. After obtaining access to vulnerable Exchange servers, the actor executed a malicious DLL through rundll32.exe and used functionality consistent with credential dumping tools to obtain password material or hashes. The actor also conducted host and account reconnaissance using native Windows utilities, including commands to enumerate network connections, running processes, and cached Kerberos tickets. Observed tradecraft aligns with hands-on-keyboard post-exploitation focused on credential access and local discovery. The use of rundll32.exe to launch a DLL indicates abuse of legitimate Windows binaries for execution and defense evasion. The actor’s use of utilities such as net, netstat, tasklist, and klist demonstrates reliance on living-off-the-land techniques to survey compromised systems and identify opportunities for follow-on access. The credential-dumping behavior suggests an objective of expanding access within the victim environment and harvesting authentication material for subsequent operations. No high-confidence evidence directly supports ransomware deployment, extortion activity, or a specific national origin for this actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.