Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-34473 - Pre-auth Path Confusion leading to ACL Bypass. Requires no privileges... the attackers utilized only one of the vulnerabilities - CVE-2021-34473, to perform unauthenticated email related activity on an Exchange server. | ProxyShell is a set of three security vulnerabilities that allow an adversary to perform unauthenticated remote code execution (RCE) and email-related tasks on unpatched Microsoft Exchange servers... The three CVEs affect the on-premise Microsoft Exchange servers 2013, 2016 and 2019. | After a successful exploitation of ProxyShell, the attackers used the Exchange to distribute phishing emails to internal and external user accounts with the payload of QBot and DatopLoader. DatopLoader is a malware loader that emerged for the first time in September 2021.
CVE-2021-34523 - Elevation of Privileges on Exchange PowerShell backend. Requires no privileges. | After a successful exploitation of ProxyShell, the attackers used the Exchange to distribute phishing emails to internal and external user accounts with the payload of QBot and DatopLoader. DatopLoader is a malware loader that emerged for the first time in September 2021.
CVE-2021-31207 - Post-auth Arbitrary-File-Write leading to RCE. Requires “High” privileges. | After a successful exploitation of ProxyShell, the attackers used the Exchange to distribute phishing emails to internal and external user accounts with the payload of QBot and DatopLoader. DatopLoader is a malware loader that emerged for the first time in September 2021.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Compromised servers are then used to spread phishing emails delivering Datoploader (aka Squirrelwaffle) and the QBot trojan.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers exploited recently disclosed vulnerabilities in Microsoft Exchange Servers to gain access to the targeted networks.
and a scheduled task launching PowerShell which in turn starts regsvr32.exe in the same way.
Once it is done, an obfuscated Macro will be executed to create the C:\Datop folder
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware loader used as an initial access mechanism and payload deliverer via phishing emails, typically delivering follow-on malware including Cobalt Strike and QBot.
Datoploader is delivered through phishing ZIP/XLS lures, creates the directory C:\Datop, downloads files, executes them via regsvr32.exe, and establishes persistence via registry autorun keys or scheduled tasks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.