Threat actors used the ProxyLogon Microsoft Exchange exploit chain, including CVE-2021-26855 and CVE-2021-27065, to compromise on-premises Exchange servers and deploy the DearCry ransomware, also tracked by Microsoft as DoejoCrypt. Researchers reported victims in multiple countries, and at least one victim was asked to pay $16,000. The activity followed earlier Exchange intrusions in which attackers had already planted web shells, reinforcing warnings that organizations should assume compromise even after applying Microsoft’s patches.
Analysis from CISA and Sophos shows DearCry is a relatively simple, human-operated Windows ransomware that encrypts files across connected drives using per-file AES-256 keys protected by a hard-coded RSA-2048 public key, appends encrypted metadata to files, renames them with the .CRYPT extension, and drops a readme.txt ransom note. CISA found the malware enumerates drives from A: through Z:, temporarily runs as a service named msupdate, overwrites originals with 0x41 before deletion, and includes contact emails konedieyp@airmail.cc and uenwonken@memail.com; Sophos also noted victim-specific builds, no need for command-and-control to start encryption, and a file-header format resembling WannaCry without evidence of a shared author.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
CISA published malware analysis report MAR-10330097 on April 12, 2021, documenting six DearCry samples, their encryption behavior, ransom note details, and YARA detection logic.
Sophos detected and blocked a DearCry ransomware attack against a customer network in Austria on March 13, 2021, after the same Exchange server had already been targeted with a webshell.
Sophos blocked webshell activity on an Austrian customer's Exchange server on March 11, 2021, two days before a DearCry ransomware attempt on the same system.
A victim reported on March 9, 2021, that their Microsoft Exchange server had been compromised through ProxyLogon and that DearCry was the payload.
Other DearCry samples later documented by CISA had compile timestamps on March 9, 2021, showing multiple closely related variants were built around the same time.
Michael Gillespie of ID-Ransomware began receiving victim submissions tied to DearCry on March 9, 2021, with most cases involving Microsoft Exchange servers.
Several DearCry samples analyzed later by CISA had compile timestamps on March 8, 2021, indicating active malware development before broad public reporting.
Microsoft released an out-of-band patch on March 3, 2021, after Volexity reported active exploitation of the Exchange vulnerabilities.
MSRC confirmed on February 18, 2021, that the Exchange bug would be fixed in the March 9 Patch Tuesday release.
Volexity assessed that attackers began exploiting the Exchange vulnerabilities in the wild as early as January 6, 2021, including deployment of ASPX webshells and follow-on post-exploitation activity.
DEVCORE contacted the Microsoft Security Response Center on January 5, 2021, and set a 120-day public disclosure deadline.
DEVCORE chained the Exchange bugs into a pre-authentication remote code execution exploit dubbed ProxyLogon on January 1, 2021.
DEVCORE researchers uncovered the Exchange vulnerabilities later used in the ProxyLogon chain and reported them to Microsoft in December 2020.
Microsoft security researcher Phillip Misner confirmed that DearCry, which Microsoft tracks as DoejoCrypt, was being installed in human-operated attacks using the Exchange exploits.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourceus-cert.cisa.gov
Open sourcebleepingcomputer.com
Open sourcesophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.