Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Our telemetry showed three malware families taking advantage of the ProxyLogon vulnerability beginning in March: the coinminer LemonDuck was sighted first, quickly followed by the ransomware BlackKingdom, then the Prometei botnet.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Our telemetry showed three malware families taking advantage of the ProxyLogon vulnerability beginning in March... Leveraging the ProxyLogon vulnerability allowed the threat actors behind BlackKingdom, Prometei, and LemonDuck to execute Chopper web shells
Leveraging the ProxyLogon vulnerability allowed the threat actors behind BlackKingdom, Prometei, and LemonDuck to execute Chopper web shells... The China Chopper web shell... continues to be widely used by threat actors in their campaigns to gain remote access to a targeted system.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that encrypts servers and files, uses random file extensions, drops a ransom note named decrypt_file.TxT, and demands $10,000 in Bitcoin. The content explicitly states it exploited Microsoft Exchange Server ProxyLogon vulnerabilities to encrypt servers.
Named as one of the ransomware families with low prevention rates in the testing data; no further technical detail provided.
A ransomware family observed exploiting ProxyLogon against unpatched Microsoft Exchange servers. In the described chain it used ExchDefender.exe, created the MSExchangeDefenderPL service, removed competing web shells, deployed a Chopper web shell via Offline Address Book modification, and then delivered its ransomware payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.