Ruler is an open-source Exchange and Outlook post-compromise exploitation framework and persistence tool. The content describes it as a publicly available framework used against Microsoft Exchange and Office 365/Exchange Online environments after account compromise. Its documented capabilities include configuring malicious Outlook folder Home Pages, inserting malicious custom forms into a user’s Outlook mailbox, and creating malicious mailbox rules or forms that sync from the mailbox to Outlook clients. These mailbox-resident artifacts can survive password resets and even client reinstallation because they are re-synchronized from Exchange. The technique can be used to execute remote or custom code on Outlook clients, including applications hosted on remote WebDAV servers, and the content cites PowerShell Empire as an example payload installed through this mechanism. Ruler is associated in the provided content with Iranian threat activity: MuddyWater attempted to use the framework against a Middle Eastern telecommunications target, and prior usage was noted with APT33, which used compromised Office 365 accounts together with Ruler in attempts to gain control of endpoints. The content also notes phishing and password spraying as common initial account-compromise vectors enabling this post-compromise abuse. High-confidence detection and investigation references in the content include Outlook mailbox artifacts such as message classes IPM.Rule.Version2.Message and IPM.Microsoft.FolderDesign.FormsDescription, the NotRuler defensive toolkit and its published IOCs, and registry overrides that can re-enable unsafe Outlook rule actions via EnableUnsafeClientMailRules under HKCU\Software\Microsoft\Office\16.0\Outlook\Security\ or HKCU\Software\Microsoft\Office\15.0\Outlook\Security.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-21378 exposes a critical vulnerability in Microsoft Outlook, allowing for authenticated remote code execution (RCE) through the manipulation of synced form objects.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints.
The attackers attempt to exploit Exchange servers using two different tools: A publicly available script for exploiting CVE-2020-0688 (T1190) Ruler – an open source Exchange exploitation framework.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Assuming the lists of credentials are valid, the mass collection confirms our hypothesis that the OilRig group maintains a heavy emphasis on credential based attacks... once the adversary gains access via legitimate credentials, they are able to masquerade as a legitimate user
"This means, we have a full VBScript engine available to us... CreateObject(\"Wscript.Shell\").Run \"calc.exe\""
We also found the threat actor using the open-source tool ruler to brute force email accounts and passwords... We also identified another Python script that the actor used to exfiltrate emails from a Zimbra mail server.
insert special-crafted records to a user mailbox to abuse the user’s Microsoft Outlook functions and make it execute arbitrary commands or code.
Assuming the lists of credentials are valid, the mass collection confirms our hypothesis that the OilRig group maintains a heavy emphasis on credential based attacks... once the adversary gains access via legitimate credentials, they are able to masquerade as a legitimate user
They do this by tricking the form's setup process, changing registry keys and files to get past Outlook's security.
Assuming the lists of credentials are valid, the mass collection confirms our hypothesis that the OilRig group maintains a heavy emphasis on credential based attacks... once the adversary gains access via legitimate credentials, they are able to masquerade as a legitimate user
Assuming the lists of credentials are valid, the mass collection confirms our hypothesis that the OilRig group maintains a heavy emphasis on credential based attacks... once the adversary gains access via legitimate credentials, they are able to masquerade as a legitimate user
"If you compromise an account, install a custom form and that is it... all you need to do to trigger the shell again is to send an email with the correct message class." | "This attack has typically relied on using Outlook Rules to trigger the shell execution."
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source Exchange exploitation framework used here to attempt creation of malicious forms against Exchange environments.
A tool used alongside compromised Office 365 accounts to help gain control of endpoints.
Post-exploitation tool used to abuse Microsoft Outlook by inserting malicious custom forms or creating malicious mailbox rules that can trigger code execution (e.g., spawning mshta.exe or PowerShell) on Outlook startup or upon receipt of crafted emails.
Tool used to abuse Outlook features (e.g., Folder Home Page) for persistence and code execution when a targeted folder is accessed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.