Researchers and incident responders linked multiple U.S. intrusions to the Iranian threat actor PHOSPHORUS (also tracked as APT35, DEV-0270, NemesisKitten, and UNC2448), which repeatedly exploited vulnerable Microsoft Exchange servers using the ProxyShell chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207). In observed cases, the actor deployed web shells, created local administrator accounts, enabled RDP access, disabled defenses, and used native Windows tools for rapid discovery and credential theft, including LSASS dumping. Investigators also saw Go-based and modified Fast Reverse Proxy (FRP) payloads masquerading as legitimate files such as dllhost.exe, along with newer malware including user.exe, task_update.exe, and Conser.exe, plus the installation of a fake Microsoft-themed root certificate in at least one variant.
The activity escalated beyond espionage-style access into disruptive operations. One DFIR case showed PHOSPHORUS moving from initial Exchange compromise to domain-wide encryption in roughly 42 hours, using BitLocker on servers and DiskCryptor on workstations before leaving an $8,000 ransom demand. Secureworks separately reported COBALT MIRAGE, an Iran-linked cluster associated with the same broader ecosystem, conducting ransomware operations in the United States. Deep Instinct and other researchers said the actor continued to refine mass-exploitation tooling and traffic evasion, including FRP communications that blended connections to legitimate domains with visually similar attacker-controlled infrastructure, while overlaps were also noted with exploitation tied to Fortinet CVE-2018-13379 and Log4Shell.

TTPs, infrastructure, and targeting history in one profile.
13 events from the most recent confirmed update back to the earliest known activity.
Team Cymru reported that PHOSPHORUS-linked exploitation activity associated with C2 IP 107.173.231.114 continued as of 29 November 2022. The telemetry included a likely opportunistically compromised South Asian Exchange victim and additional potential victims in Africa and the Middle East communicating with the C2 and Kaspersky-hosted infrastructure in patterns consistent with prior PHOSPHORUS malware.
In June 2022, Secureworks analyzed a ransomware incident in which COBALT MIRAGE exploited ProxyShell on Microsoft Exchange, deployed multiple web shells and the TunnelFish FRPC variant, enabled DefaultAccount, and encrypted several servers with BitLocker. Recovered artifacts included ransom notes and C2 infrastructure that supported attribution and linked the activity to additional Iranian-associated infrastructure.
In the 2021-10 to 2022-02 campaign, Deep Instinct identified previously unknown variants of user.exe, task_update.exe, and FRPC, along with an additional .NET payload named Conser.exe. The tooling created local admin access, enabled RDP, installed a fake Microsoft-impersonating root certificate in one variant, and established reverse-proxy or SSH tunnels.
Deep Instinct concluded that in early 2022 PHOSPHORUS began using FRPC variants that generated traffic to both legitimate domains and visually similar attacker-controlled domains to hide malicious communications. The technique blended attacker traffic with benign-looking network activity.
Also in December 2021, the attackers used comsvcs.dll to dump LSASS, compressed the dump into ssasl.zip, and exfiltrated it through the web shell. Investigators evicted the actor before additional impact was observed.
In the December 2021 case, the actor created a local DefaultAccount user, added it to Administrators and Remote Desktop Users, enabled RDP, and disabled multiple Windows Defender protections. They also enabled WDigest and disabled LSA protection to facilitate credential theft.
During the December 2021 intrusion, the attackers uploaded Wininet.xml, created a scheduled task named \Microsoft\Windows\Maintenance\Wininet, and downloaded a fake dllhost.exe from 148.251.71[.]182. The Go-based payload communicated with msupdate[.]us subdomains and showed FRP code overlap.
In December 2021, investigators observed a PHOSPHORUS-related intrusion exploiting the ProxyShell chain to gain initial access to a Microsoft Exchange server and deploy multiple IIS-accessible ASPX web shells. The activity occurred in two bursts within a three-day window and appeared automated.
Between 2021-10-30 and 2022-02-12, Deep Instinct observed seven attempts to exploit a Microsoft Exchange server at a U.S. infrastructure and construction company and attributed the activity to PHOSPHORUS. All seven attempts were prevented in the customer environment.
Still in late September 2021, the intrusion culminated in domain-wide encryption: servers were encrypted with BitLocker via setup.bat and workstations with DiskCryptor. The report said time-to-ransom from first successful ProxyShell exploitation was about 42 hours.
In the same late-September 2021 case, the attackers dumped LSASS, packaged the dump, and about 30 minutes later began using a domain administrator account. They then scanned internally and moved laterally, primarily over RDP.
During the late-September 2021 intrusion, the actors enabled the built-in DefaultAccount, added it to Administrators and Remote Desktop Users, and used Plink plus FRP masquerading as dllhost.exe to tunnel RDP and maintain access. They also created a scheduled task for persistence.
In late September 2021, attackers attributed to PHOSPHORUS exploited the ProxyShell chain against an on-premises Microsoft Exchange server, deployed multiple web shells, and began discovery activity. The intrusion unfolded over roughly three days.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 119 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
secureworks.com
Open sourceteam-cymru.com
Open sourcemicrosoft.com
Open sourcedeepinstinct.com
Open sourcesecureworks.com
Open sourcethedfirreport.com
Open sourcetrendmicro.com
Open sourcemicrosoft.com
Open sourcethedfirreport.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.