Attackers exploited unpatched on-premises Microsoft Exchange servers using ProxyLogon and ProxyShell flaws, including CVE-2021-26855, CVE-2021-34473, and CVE-2021-34523, to hijack legitimate email conversations and send phishing replies from real user accounts. Investigations found the activity on compromised Exchange servers in multiple intrusions, with attackers accessing mailbox data, impersonating users, and distributing links to ZIP archives containing malicious Word or Excel documents. In several cases, the emails were sent internally or from trusted accounts, helping the campaign bypass normal mail defenses; one investigation also identified attacker-created Outlook items marked with the unusual IPM.Blabla class.
The phishing chain delivered Squirrelwaffle, a loader that used malicious Office files and Excel 4.0 macros to fetch DLL payloads, often executed with regsvr32, leading to follow-on infections including QakBot, Cobalt Strike, and fileless registry-based stagers with scheduled-task persistence. Researchers linked the campaign to compromised WordPress infrastructure, anti-analysis controls, and command-and-control traffic that exfiltrated obfuscated host data, while one incident escalated beyond malware delivery into attempted payment redirection through a typo-squatted domain in a business email compromise-style fraud scheme. Defenders were urged to patch Exchange comprehensively, hunt for post-exploitation artifacts such as web shells and malicious mailbox activity, and harden email authentication controls including SPF, DKIM, and DMARC.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
19 events from the most recent confirmed update back to the earliest known activity.
On December 17, 2021, Trend Micro published analysis of a fileless QAKBOT stager that used PowerShell, registry-stored payloads, scheduled-task persistence, and flexible remote tasking.
On November 19, 2021, Trend Micro published research detailing how Squirrelwaffle operators exploited ProxyLogon and ProxyShell on Exchange servers in the Middle East to hijack internal email chains and distribute malware.
Certitude reported that in early November 2021, a customer discovered internal and external users receiving suspicious reply emails sent from their own legitimate mail accounts through an on-premises Exchange server.
On October 26, 2021, Cisco Talos published analysis describing SQUIRRELWAFFLE's malspam delivery, compromised WordPress infrastructure, and use as an initial access loader for Qakbot and Cobalt Strike.
Talos observed campaign volume begin ramping up on September 13, 2021, followed by daily malicious spam runs distributing the loader.
Talos reported that the earliest files associated with the SQUIRRELWAFFLE campaigns were believed to have been submitted to public malware repositories on September 10, 2021.
Cisco Talos observed one distribution server with ANTIBOT deployed on September 8, 2021, shortly before SQUIRRELWAFFLE campaigns launched from that server.
Researchers reported that SQUIRRELWAFFLE emerged in mid-September 2021 as a malware loader spread through hijacked email threads and malicious Office documents. It was observed delivering follow-on payloads including Qakbot and Cobalt Strike.
Trend Micro said Microsoft stated that May or July 2021 updates were needed to protect Exchange servers from ProxyShell vulnerabilities.
Trend Micro noted that Microsoft released patches for the ProxyLogon vulnerabilities affecting Exchange Server in March 2021.
Trend Micro described QAKBOT as a banking trojan and infostealer that cybercriminals have used since 2007.
In the Sophos case, attackers stole a legitimate payment-related email thread, registered a typo-squatted domain, and continued the conversation outside the victim's infrastructure to redirect a customer payment. The transfer was nearly completed but was stopped after a financial institution flagged it as fraudulent.
Sophos Rapid Response investigated an incident in which attackers exploited an unpatched Exchange server with ProxyLogon and ProxyShell, then used thread hijacking to mass distribute Squirrelwaffle to internal and external recipients.
Trend Micro's incident response and XDR teams found that one of Squirrelwaffle's payloads included QAKBOT, and assessed the newly analyzed fileless stager as possibly connected to that campaign. The stager could also fetch and execute additional malware families, including potentially ransomware.
During a threat hunting initiative, Trend Micro researchers found a fileless stager that stored encoded commands and payload components in the Windows registry, achieved persistence via a scheduled task, and dropped a QAKBOT DLL via regsvr32.exe. They said it was the first time they had encountered this kind of fileless stager with persistence.
Certitude's investigation found an unpatched Exchange server exposed to ProxyLogon and ProxyShell, with IIS logs showing SSRF exploitation of CVE-2021-26855 and attacker-created emails marked with the Outlook ItemClass value "IPM.Blabla." The phishing links matched patterns associated with attacks assessed as related to the Squirrelwaffle campaign.
Trend Micro observed malicious emails linking to ZIP archives containing Excel 4.0 macro spreadsheets that downloaded a DLL related to Qbot. The DLL was executed with regsvr32.exe, injected into mobsync.exe, and communicated with 24.229.150.54:995.
Investigators found evidence that attackers exploited CVE-2021-26855, CVE-2021-34473, and CVE-2021-34523 on compromised Exchange servers to access mailbox data, obtain user SIDs and email addresses, and send malicious replies within legitimate threads.
Trend Micro Incident Response investigated several Squirrelwaffle-related intrusions in the Middle East involving on-premises Exchange servers vulnerable to ProxyLogon and ProxyShell. In one case, all internal users received malicious replies sent through compromised internal Exchange infrastructure.
5 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcetrendmicro.com
Open sourcetrendmicro.com
Open sourcecertitude.consulting
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.