Security researchers detailed how Microsoft Exchange web interfaces can be abused to extract broad Active Directory data by leveraging Exchange-exposed RPC functionality, turning an Internet-facing mail server into a proxy for directory reconnaissance. The research reviewed earlier Exchange attack paths involving Autodiscover, Offline Address Books, EWS, PrivExchange, and Office Web Add-ins, then highlighted RPC over HTTP v2 as a more flexible technique that can work with any domain account without requiring mailbox access or Autodiscover.
The attack abuses Exchange support for the MS-OXABREF and MS-OXNSPI protocols to enumerate address books and query directory information that Exchange can see, including Domain Controller Distinguished Name Tags that enable large-scale Active Directory record dumping. Researchers also tied Exchange abuse to escalation paths that can put attackers one API call away from domain administrator privileges, and released tooling improvements in Impacket such as rpcmap.py enhancements and a new exchanger.py utility; they warned organizations not to expose Exchange directly to the Internet and recommended restricting access with VPNs or client certificates.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
The research operationalized the technique by adding RPC over HTTP v2 enumeration capabilities to rpcmap.py and creating a new exchanger.py utility, which the article says was later made available in the Impacket repository.
Positive Technologies published research showing that Exchange-exposed RPC over HTTP v2 can be abused to access MS-OXABREF and MS-OXNSPI, allowing low-privilege accounts, including accounts without mailboxes, to enumerate address books and retrieve broad Active Directory data through Exchange.
The Positive Technologies article states that Dirk-jan Mollema released PrivExchange along with an NTLMRelayX update to relay Exchange-originated HTTP authentication to LDAP for Active Directory write access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.