7zip_and_netsupport_manager_attacker is an intrusion cluster associated with exploitation of the 2021 Microsoft Exchange Server vulnerabilities CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. The activity reflects opportunistic post-compromise operations conducted after internet-facing Exchange servers were breached and webshell access was established. The actor used a renamed 7-Zip utility together with NetSupport Manager, indicating use of legitimate tools for archive handling, remote access, and likely staging or exfiltration of collected data. Observed tradecraft includes exploitation of a public-facing application for initial access, deployment of webshells for command execution, ingress tool transfer, use of PowerShell to retrieve additional payloads, and execution of remote administration software. The actor’s tooling and behavior fit a broader pattern seen during mass Exchange exploitation in which attackers combined living-off-the-land techniques with commodity or dual-use utilities to reduce detection. Use of compression software alongside a remote access tool is consistent with hands-on-keyboard post-exploitation, operational staging, and potential data theft. Available information does not support a confident attribution to a specific named threat actor or state sponsor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.