ProxyShellMiner is a botnet malware family identified in reporting on routinely exploited vulnerabilities. It was listed by CISA and partner agencies as one of the botnets observed exploiting the top routinely exploited vulnerabilities in 2022. The provided content specifically associates ProxyShellMiner with exploitation activity against widely abused public vulnerabilities, including the ProxyShell attack chain affecting Microsoft Exchange (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), which was heavily exploited across the threat landscape. The content does not provide further high-confidence details on its payload behavior, infection chain, persistence mechanisms, targeted sectors, or specific indicators of compromise beyond its identification as a botnet exploiting these vulnerabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ProxyShellMiner is a botnet malware that exploits the ProxyShell vulnerabilities in Microsoft Exchange servers to mine cryptocurrency and potentially facilitate further attacks.
ProxyShellMiner is a botnet malware that exploits the ProxyShell chain of vulnerabilities in Microsoft Exchange to mine cryptocurrency and potentially facilitate further attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.