Researchers reported intrusions against Middle East government environments that abused unpatched Microsoft collaboration servers to gain long-term access. One campaign documented by Secureworks exploited Microsoft Exchange vulnerability CVE-2020-0688, deploying multiple web shells, reusing compromised administrator credentials, moving between Exchange and SharePoint servers, dumping credentials from a certificate authority server and domain controller, and exfiltrating data through a compromised Exchange host. Secureworks said the activity persisted through at least April 2021 and assessed with moderate confidence that the Exchange-related operation was likely tied to an Iranian threat group, possibly COBALT GYPSY.
The reporting also linked the victim set to earlier exploitation of Microsoft SharePoint. Secureworks found a separate 2019 compromise that abused CVE-2019-0604 on SharePoint and concluded it was likely unrelated to the later Exchange intrusion, indicating different threat actors targeted the same environment over time. Separate reporting from Palo Alto Networks Unit 42 described Emissary Panda attacks against Middle East government SharePoint servers, underscoring how exposed SharePoint and Exchange systems in the region were repeatedly used as entry points for espionage-focused operations.

See the actors and campaigns active against you right now.
12 events from the most recent confirmed update back to the earliest known activity.
Secureworks CTU observed continuation of CVE-2020-0688-related intrusion activity through at least April 2021. The activity may have persisted as late as June 2021.
During an April 2021 threat hunting engagement, Secureworks incident responders found web shells on multiple hosts in a customer environment. They also identified evidence of a previous SharePoint compromise and ongoing activity initially enabled by compromised on-premises Exchange servers.
The attacker uploaded an s.aspx web shell to the same SharePoint servers that had been exploited in April 2019. Secureworks reported that s.aspx had the same functionality as services.aspx.
Using the compromised accounts and hostname, the attacker conducted additional intrusion activity on a critical business server and deployed a web shell named service.aspx, followed by a second web shell named services.aspx. Secureworks found that services.aspx borrowed code from the HighShell and HyperShell web shells associated with COBALT GYPSY.
About three months after the early-2021 Exchange activity, the attacker re-entered the environment using the same hostname and compromised credentials to upload the TransportClient.dll web shell. Secureworks named this IIS-module web shell SheepTransportShell and observed related PowerShell activity creating the splsvc named pipe and, in one variant, a scheduled task named Google Updater.
In early 2021, the same owafont.aspx web shell was installed on other Exchange Servers, likely using the same compromised administrator account. This indicated expansion of the Exchange intrusion within the environment.
Secureworks discovered that a basic file upload and command execution web shell named owafont.aspx was installed on an Exchange Server in late 2020. Initial access to the Exchange environment was likely achieved by exploiting CVE-2020-0688.
Third-party researchers also reported in November 2020 that threat actors were targeting organizations using CVE-2020-0688. The reporting showed continued attacker interest in the Exchange vulnerability later in the year.
Third-party researchers reported in March 2020 that threat actors were targeting organizations via CVE-2020-0688, a remote code execution vulnerability in Microsoft Exchange Server. This established active exploitation of the flaw in the wild.
From June 2019 to June 2020, several C# web shells were installed on the previously compromised SharePoint servers in the same directories as the earlier China Chopper shells. Secureworks found no evidence linking these later C# shells to the earlier SharePoint web shell deployment.
In April 2019, a threat actor compromised several SharePoint servers in the customer environment by exploiting CVE-2019-0604. The intrusion resulted in deployment of multiple web shells, including China Chopper variants.
Secureworks assessed with moderate confidence that the later Exchange-led intrusion was likely conducted by an Iranian threat group, possibly COBALT GYPSY. The firm also assessed that the 2019 SharePoint activity and the later Exchange activity were unrelated and likely conducted by different threat groups.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 50 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
secureworks.com
Open sourcenorfolkinfosec.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.