Conti affiliates compromised an unpatched on-premises Microsoft Exchange Server 2016 by exploiting the ProxyShell vulnerability chain, then established multiple web shells within minutes to secure persistent access. Investigators said the attackers quickly conducted reconnaissance, dumped LSASS credentials, and expanded access across the environment using a cracked domain administrator account while deploying tools including Cobalt Strike and AnyDesk.
Over about five days, the intruders exfiltrated nearly 1 TB of data using Rclone and Mega before launching Conti ransomware across the victim’s Windows network. The encryption phase was executed through batch scripts run from four servers, and the intrusion closely matched tactics documented in leaked Conti affiliate playbooks, underscoring how outdated Exchange cumulative updates left the organization exposed.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
After roughly five days in the environment, the attackers launched batch files from four servers to execute the ransomware payload across administrative shares on Windows systems. Sophos said the Conti ransomware was deployed to every machine on the victim network.
Within 48 hours of initial access, the operators exfiltrated roughly 1 terabyte of data from multiple servers. On the third day, they deployed Rclone and used a PowerShell script to copy data to Mega.
After obtaining domain administrator access, the attackers moved laterally via RDP and deployed persistence and remote access tooling including AnyDesk, Cobalt Strike, Splashtop, Remote Utilities, and the Atera Agent. Sophos reported that at least seven backdoors were installed during the intrusion.
Within 30 minutes of compromise, the attackers enumerated computers, domain controllers, and domain administrators, then used additional reconnaissance commands. Within about four hours, they dumped LSASS credentials and soon used a cracked domain administrator account for lateral movement.
Sophos observed a Conti affiliate gain initial access by exploiting ProxyShell vulnerabilities on an on-premises Microsoft Exchange Server 2016 system that was running an outdated cumulative update. The attackers established an initial remote web shell in under one minute and a backup web shell three minutes later.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.