SessionManager is a custom backdoor malware that targets compromised Microsoft Exchange servers by masquerading as a legitimate Internet Information Services (IIS) module. It has been observed since at least March 2021 and was reportedly used for roughly 15 months to maintain persistent, covert access on already-hacked Exchange systems, including deployments following exploitation of ProxyLogon vulnerabilities. The malware is designed to inspect inbound HTTP requests for specially crafted data, including variants that parse commands from a crafted Cookie field, allowing operators to receive hidden instructions without initiating suspicious outbound traffic. Reported capabilities include command execution, file upload and download, collecting emails, adding further malicious access, and using the compromised web server as a proxy to communicate with additional systems on the network. Its placement among legitimate IIS files and its use of normal-looking HTTP traffic make it difficult to detect through standard monitoring. Kaspersky reported 34 infected servers across 24 organizations, with infections dating back to March 2021 and 20 organizations still infected at the time of reporting. Reported victims included NGOs, government, military, and industrial organizations across Africa, South America, Asia, Europe, Russia, and the Middle East. Unit 42 also observed SessionManager in intrusion cluster CL-STA-0046 targeting a Southeast Asian government environment, where it was used alongside OwlProxy, web shells, Cobalt Strike, Meterpreter, Earthworm, and SpoolFool; Unit 42 attributed that cluster to Gelsemium with moderate confidence, noting the rare SessionManager and OwlProxy pairing had been associated with that group in prior reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom IIS backdoor used for command execution, file upload/download, and proxying communications through a compromised web server by parsing specially crafted HTTP Cookie values.
Malware/backdoor used in the Gelsemium-attributed cluster; observed targeting vulnerable IIS servers and used to maintain access.
A stealthy malicious IIS module used to backdoor compromised Microsoft Exchange servers. It provides persistent and covert access by responding to specially crafted HTTP requests, allowing operators to collect emails, add further malicious access, and control the compromised machine while blending in with normal web server activity.
Backdoor malware that masquerades as an IIS module, deployed after exploiting ProxyLogon vulnerabilities in Microsoft Exchange servers to provide persistent access and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.