Microsoft disclosed and patched four actively exploited on-premises Exchange Server vulnerabilities — CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 — after investigators linked the initial intrusion wave to the China-linked HAFNIUM group. The flaws, later widely known as ProxyLogon, affected Exchange Server 2013, 2016, and 2019, with a defense-in-depth update also issued for Exchange 2010. Researchers said exploitation had begun by early January and rapidly expanded after public disclosure, with multiple threat actors using the bugs to gain remote access, drop web shells including China Chopper variants, steal email and files, dump credentials, and move laterally across victim networks.
Security agencies and vendors warned that patching alone did not remove attacker access because many servers had already been backdoored, prompting urgent guidance to review Exchange HttpProxy and IIS logs, hunt for suspicious w3wp.exe child processes, PowerShell abuse, LSASS dumping, and unauthorized admin creation. The campaign hit organizations globally, including Norway’s parliament, and U.S. authorities later obtained court approval for an FBI operation that removed malicious web shells from hundreds of vulnerable U.S.-based Exchange servers. Microsoft, CISA, the FBI, and incident responders urged defenders to patch immediately, restrict exposure where possible, and conduct full compromise assessments because mass exploitation continued well beyond the initial disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
25 events from the most recent confirmed update back to the earliest known activity.
The U.S. Department of Justice announced charges against four Chinese nationals working with the Ministry of State Security in a global computer intrusion campaign. NPR later referenced this action in the context of public attribution of the Exchange attack to Chinese government-backed hackers.
Belgium's Federal Public Service Interior disclosed that it had been the victim of a cyber-espionage campaign discovered after the March Exchange revelations, with Belgian experts saying the intrusion showed signs suggesting Chinese involvement. The ministry said attacker access had been stopped, malware removed, and the incident contained while the investigation continued.
The FBI executed a court-authorized operation to copy and remove malicious web shells from hundreds of vulnerable U.S.-based on-premises Exchange servers. The action targeted shells left by one early hacking group but did not patch the underlying vulnerabilities or remove other malware.
Sophos reported that attackers exploited ProxyLogon vulnerabilities at a large North American enterprise on March 16, 2021, then conducted credential dumping, lateral movement, persistence, and repeated Cobalt Strike deployment attempts. After the victim engaged Sophos on April 2, responders contained the intrusion before what Sophos assessed was likely ransomware delivery.
Imperva said that after the March 2, 2021 Exchange disclosures it observed more than 44,000 scanning and exploitation-attempt sessions for CVE-2021-26855 from over 1,600 unique source IPs. Its analysis showed worldwide targeting across industries, with the United States the most targeted country, and detailed common exploit paths including /autodiscover/autodiscover.xml, /EWS/Exchange.asmx, and /mapi/emsmdb.
Microsoft published analysis showing that multiple state-sponsored and criminal groups were exploiting Exchange vulnerabilities for follow-on activity including web shells, credential theft, ransomware, cryptomining, persistence, and data exfiltration. The report named HAFNIUM, DoejoCrypt, Lemon Duck, and Pydomer, and said Microsoft had also released a one-click Exchange On-Premises Mitigation Tool and integrated mitigations into Defender Antivirus.
Germany's Federal Office for Information Security (BSI) published version 2.4 of its guidance document on Microsoft Exchange vulnerabilities focused on detection and response. The notice made the updated PDF guidance available for defenders responding to the ongoing Exchange exploitation wave.
Norway's parliament, the Storting, announced a new cyberattack in which threat actors exploited the Exchange vulnerabilities and extracted data. The organization said the full scope was still under investigation and that it was responding with security authorities.
The FBI and CISA released a Joint Advisory on compromise of Microsoft Exchange Server. The advisory provided detection and remediation guidance as exploitation spread broadly.
Splunk Threat Research released a HAFNIUM analytic story in Enterprise Security Content Update version 3.16 to help defenders detect related activity. The release added detection content during the active response period.
The European Banking Authority announced it had been the subject of a cyberattack against its Microsoft Exchange servers. The disclosure showed the campaign had impacted a prominent regional institution.
After releasing the patches, Microsoft published additional mitigation guidance for affected Exchange customers. The guidance accompanied the emergency response to widespread active exploitation.
As of March 4, 2021, Unit 42 had identified 81 unique matching China Chopper-related samples on VirusTotal tied to the Exchange attacks. The samples supported analysis of web shell keys, timestamps, and victim diversity.
Volexity published "Operation Exchange Marauder," providing an early in-depth public analysis of the Exchange attacks. Unit 42 cited this report as an early public technical analysis of the campaign.
Microsoft disclosed that the China-based state-sponsored group HAFNIUM was the primary actor it had seen exploiting the Exchange zero-days at the time. It also warned that other nation-state and criminal groups would likely move quickly to exploit unpatched systems.
Microsoft released patches for four actively exploited Exchange Server vulnerabilities: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. Microsoft also issued a defense-in-depth patch for Exchange Server 2010 addressing CVE-2021-26857.
CISA issued Emergency Directive 21-02 after determining the actively exploited on-premises Microsoft Exchange vulnerabilities posed an unacceptable risk to federal civilian agencies. The directive required agencies to identify Exchange servers, perform forensic triage, disconnect compromised or untriaged systems when necessary, apply Microsoft patches, and report incidents and status to CISA.
Unit 42 found OAB file modification times showing two distinct clusters of compromises on February 28 and March 1, 2021, before broad public news about the vulnerabilities. The timing and related keys suggested rapid, likely automated deployment of China Chopper web shells.
The campaign shifted from targeted intrusions to global mass scanning on February 26 and 27, 2021, after which attackers rapidly installed web shell backdoors on vulnerable Exchange servers at scale. The article says this late-February surge led to tens of thousands of compromises within days.
Orange Tsai said he had reported a pre-authenticated remote code execution chain to a vendor. Microsoft later credited him in the CVEs released for the Exchange vulnerabilities.
Volexity later updated its reporting to say exploitation of the initial Exchange vulnerability was observed as early as January 3, 2021. Unit 42 likewise said the earliest indications of exploitation dated back to January 3.
Steven Adair of Volexity discovered suspicious activity on a customer's Microsoft Exchange server in January and identified unexpected requests for email accounts and confidential files, then reported it to Microsoft. This marked an early detection of the campaign before public disclosure.
DevCore discovered a pre-authentication proxy vulnerability in Microsoft Exchange Server that it named ProxyLogon. The flaw was later tracked publicly as CVE-2021-26855 and became part of the Exchange exploit chain disclosed in March 2021.
FireEye published analysis of the China Chopper web shell, a malware family later seen in the Exchange exploitation campaign. This established historical context for the web shell used in 2021 Exchange compromises.
Symantec reported post-compromise investigations at customer environments affected via the Exchange vulnerabilities, including a Middle East telecommunications company with activity dating to January 2021 and a Southeast Asia legal-sector victim first seen on February 28, 2021. The cases included China Chopper web shells, credential dumping, Cobalt Strike, PsExec, Mimikatz, ProcDump, and in one instance shadow-copy deletion consistent with possible ransomware preparation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
35 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcenews.sophos.com
Open sourcenpr.org
Open sourcedevco.re
Open sourcevolexity.com
Open sourcei.blackhat.com
Open sourcepraetorian.com
Open sourcecve.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.