Pawn Storm—also tracked as APT28 and Forest Blizzard—conducted sustained operations against high-value organizations by combining spear-phishing with large-scale Net-NTLMv2 hash relay activity targeting Microsoft Exchange environments. Trend Micro reported that from roughly April 2022 through November 2023, the group repeatedly targeted government bodies and critical sectors including foreign affairs, energy, defense, transportation, finance, local government, courts, and central banking, with victims spanning Europe, North America, South America, Asia, Africa, and the Middle East.
The campaign was described as noisy but effective, using repeated authentication-relay attempts as a cost-efficient way to gain access to email accounts at scale. Reported post-compromise activity included changing mailbox folder permissions to maintain persistence and sending malicious internal emails from hijacked accounts to expand access inside victim organizations, while related guidance on detecting malicious activity against Microsoft Exchange servers underscores the focus on Exchange infrastructure as a key attack surface.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that the observed NTLMv2 hash relay activity persisted until approximately November 2023. The campaign featured major spikes in targeting volume and was associated with post-exploitation activity such as mailbox permission changes for persistence and malicious internal emails for lateral movement.
From approximately April 2022 through November 2023, Pawn Storm attempted NTLMv2 hash relay attacks at scale against high-value targets worldwide. The targeting shifted across government departments and critical sectors including foreign affairs, energy, defense, transportation, finance, local government, and military-related entities.
Beginning in May 2019, Pawn Storm used compromised high-profile email accounts to send credential-phishing spam and conducted daily probes of webmail, Exchange Autodiscover, and other email-related services worldwide. Trend Micro also linked the group to broader late-2019 scans for vulnerable Microsoft SQL Server and Directory Services hosts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourcewojsko-polskie.pl
Open sourcedocuments.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.