DearCry, also tracked by Microsoft as DoejoCrypt, is a Windows ransomware family that emerged in March 2021 during widespread exploitation of on-premises Microsoft Exchange Server vulnerabilities known as ProxyLogon, including CVE-2021-26855 and CVE-2021-27065. It was deployed in human-operated intrusions after attackers compromised vulnerable Exchange servers, often following webshell installation and broader post-exploitation activity. Reported victims spanned multiple countries, and the malware was associated with opportunistic ransomware activity leveraging the same Exchange access initially exploited by state-linked operators and later reused by criminal actors.
DearCry encrypts files across connected drives and a broad range of file types, including documents, archives, databases, images, source code, executables, configuration files, and Exchange-related data. It uses per-file AES-256 encryption with an embedded RSA-2048 public key to protect the symmetric keys, and prepends encrypted metadata to affected files. Encrypted files are renamed with a .CRYPT extension, and ransom notes are dropped as readme.txt. Analysis has also noted that DearCry prepends a distinctive marker to encrypted files and uses a file-header structure reminiscent of WannaCry, although no direct authorship link has been established. Some variants create a temporary Windows service named msupdate during encryption and remove it afterward.
The malware is considered relatively unsophisticated in implementation, with little evidence of packing, obfuscation, or mature development practices, but it remains operationally destructive. It enumerates drives from A: through Z:, overwrites original files before deletion to hinder recovery, and in later variants was observed targeting executable and library files as well, potentially rendering infected systems unusable. DearCry does not require command-and-control communication to begin encryption because the necessary public-key material is embedded in the binary. No reliable free decryption weakness has been publicly established for affected victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The bugs leveraged in the exploit—CVE-2021-26855 and CVE-2021-27065—were uncovered and reported to Microsoft in December by researchers at DEVCORE. | The bugs leveraged in the exploit—CVE-2021-26855 and CVE-2021-27065—were uncovered and reported to Microsoft in December by researchers at DEVCORE. On New Year’s Day, the DEVCORE researchers chained the bugs together and created a workable pre-authentication remote code execution exploit they dubbed “ProxyLogon.” | The exploit, initially attributed to a Chinese state-sponsored actor, has now been adopted for a range of cybercrime activities—the latest being a ransomware called DearCry. Sophos recently detected and stopped a DearCry attack using the exploit, and obtained samples for analysis.
The threat actor exploited the on-premises versions of Microsoft Exchange Server, abusing the remote code execution (RCE) vulnerability also known as ProxyLogon (CVE-2021-27065).
Microsoft Security Intelligence has released a tweet on DearCry ransomware being used to exploit compromised on-premises Exchange Servers. | CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 allow for remote code execution. CVE-2021-26858 and CVE-2021-27065 are similar post-authentication arbitrary write file vulnerabilities in Exchange. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could write a file to any path on the server.
Microsoft Security Intelligence has released a tweet on DearCry ransomware being used to exploit compromised on-premises Exchange Servers. | CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 allow for remote code execution... CVE-2021-26857 is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unsophisticated ransomware delivered following exploitation of Microsoft Exchange ProxyLogon vulnerabilities. It encrypts files using AES-256 with the AES key protected by an embedded RSA public key, writes encrypted output to .CRYPT files, drops readme.txt ransom notes, and uses a hybrid copy-plus-overwrite approach that hinders file recovery. It does not require C2 to begin encryption and appears to have victim-specific builds/keys.
Unsophisticated ransomware that mimics WannaCry and exploits Exchange server vulnerabilities.
Referenced as another ransomware previously reported targeting vulnerable Exchange servers.
Ransomware previously reported targeting vulnerable Exchange servers; mentioned here only as background comparison to Black KingDom.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.