Attackers exploited the ProxyNotShell chain on on-premises Microsoft Exchange Server by combining CVE-2022-41040, an authenticated SSRF flaw, with CVE-2022-41082, a remote code execution bug reachable through Exchange PowerShell remoting. Microsoft confirmed that Exchange Server 2013, 2016, and 2019 were affected, and the flaws were reported as being used against critical infrastructure before patches were released. The intrusion path exposed the Exchange PowerShell endpoint through crafted requests and then abused WSMAN and XML SOAP traffic to establish remote shell access.
Observed post-exploitation activity included reconnaissance, DLL hijacking attempts, remote process injection, persistence, and reverse shell deployment. Investigators also documented deserialization-based execution triggered through a crafted address book request, along with malicious DLLs and binaries, a reverse proxy executable, and command-and-control infrastructure including 193.149.185.52:443 and sync.service.auzreservices.com, indicating that successful exploitation quickly progressed from initial access to hands-on-keyboard control.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2022-10-11, Microsoft released patches for the Exchange zero-days CVE-2022-41040 and CVE-2022-41082 after in-the-wild exploitation had been observed.
Kaspersky observed successful exploitation of the vulnerabilities followed by reconnaissance, DLL hijacking attempts, remote process injection, persistence, and reverse shell activity, and published related indicators of compromise including malicious files and C2 infrastructure.
Microsoft later confirmed that Exchange Server 2013, 2016, and 2019 were affected by the ProxyNotShell attack chain involving CVE-2022-41040 and CVE-2022-41082.
GTSC reported that CVE-2022-41040 and CVE-2022-41082 were used together in an attack in August 2022 targeting critical infrastructure via on-premises Microsoft Exchange Server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.