Attackers exploited the Microsoft Exchange ProxyLogon vulnerability to compromise unpatched Exchange servers and install a Monero cryptominer. The campaign used already-compromised Exchange servers to host a staged batch downloader, allowing the malware to spread by targeting other vulnerable systems exposed to the internet.
The intrusion chain abused certutil.exe to decode a base64-encoded payload named QuickCPU.exe, then injected the miner into a running system process to reduce detection. Researchers found the payload contained xmr-stak components and was configured to connect over TLS to a mining pool tied to the wallet label "DRUGS," indicating an opportunistic post-exploitation operation that monetized Exchange access through illicit cryptocurrency mining.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
According to the Monero blockchain, the wallet used in the campaign began receiving funds on March 9. The miner was configured to connect over TLS to the attacker’s pool using the name "DRUGS."
While investigating customer telemetry from an Exchange server, SophosLabs identified a staged infection chain that fetched a fake ZIP batch script, used certutil.exe to decode a base64-wrapped payload into QuickCPU.exe, and injected the miner into a running process to evade detection.
SophosLabs said the unknown attacker’s campaign exploiting ProxyLogon to deploy a Monero cryptominer began around March 9. The attacker used compromised Exchange servers to host staged payloads for infecting other vulnerable Exchange servers.
Microsoft disclosed the serious Exchange Server vulnerability known as ProxyLogon, after which multiple threat actors began targeting exploitable Exchange servers with malware including webshells and ransomware.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.