At least 10 advanced persistent threat groups exploited the ProxyLogon vulnerabilities in on-premises Microsoft Exchange Server, with several attacking before Microsoft released emergency patches on March 2, 2021. The flaws affected Exchange Server 2013, 2016 and 2019 and enabled a pre-authentication remote-code-execution chain used to access email, install web shells and deploy additional malware. Microsoft initially attributed zero-day activity to HAFNIUM; ESET subsequently detected web shells on more than 5,000 email servers across over 115 countries, with government agencies and private companies among the victims. Other observed attackers included Tick, LuckyMouse, Calypso, Winnti Group, CactusPete and Mikroceen.
Exploitation expanded beyond the initial espionage campaigns. FamousSparrow began exploiting ProxyLogon the day after patches were released and used its SparrowDoor backdoor in campaigns targeting hotels, governments and other organizations. The financially motivated Prometei botnet exploited CVE-2021-26858 and CVE-2021-27065 to deploy China Chopper web shells and download malware for Monero mining, credential harvesting and lateral propagation; its backdoor capabilities also created risks of data theft and further malware delivery. Defenders were urged to patch exposed Exchange servers and investigate existing compromises: patching alone does not remove attacker access, making web-shell detection, persistence hunting and remediation essential.

See which actors are running it and whether you're in range.
18 events from the most recent confirmed update back to the earliest known activity.
ESET telemetry showed that FamousSparrow began exploiting ProxyLogon the day after Microsoft's March 2021 patch release. The group used the Exchange vulnerabilities to deploy its custom SparrowDoor backdoor.
Mikroceen, also known as Vicious Panda, compromised a Central Asian utility company's Exchange server one day after Microsoft released patches.
Microsoft released out-of-band security updates for on-premises Exchange Server 2013, 2016 and 2019 and disclosed active exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. Microsoft attributed observed attacks involving email access, data theft and persistent malware installation to HAFNIUM.
Winnti Group compromised email servers at an oil company and a construction equipment company hours before Microsoft's patch release. The intrusions involved webshells, PlugX or a loader resembling previous Winnti v.4 loaders, along with credential-dumping tools.
LuckyMouse compromised the server one day before Microsoft released patches. The attackers deployed Nbtscan and a ReGeorg webshell variant and attempted to install the SysUpdate backdoor.
ESET observed Tick exploitation beginning February 28, two days before Microsoft's patch release. Tick compromised an East Asian IT company's webserver and deployed a Delphi backdoor resembling its previous implants.
Researchers first discovered Prometei in 2020. The multi-stage botnet targets Windows and Linux systems to mine Monero and uses credential harvesting and lateral propagation techniques.
ESET traced FamousSparrow's campaigns back to August 2019. The group primarily targeted hotels, but also attacked governments, international organizations, engineering companies and law firms.
Microsoft released security updates for CVE-2021-28480, CVE-2021-28481, CVE-2021-28482 and CVE-2021-28483, four critical remote code execution vulnerabilities distinct from the March flaws. Microsoft reported no observed exploitation at release; systems already patched in March still required these updates.
ESET named FamousSparrow as a cyberespionage group and documented targets in 12 countries, linking its activity to the custom SparrowDoor backdoor. The analysis detailed DLL search-order hijacking, registry and service persistence, file exfiltration and an interactive reverse shell.
Cybereason identified an opportunistic Prometei campaign using CVE-2021-26858 and CVE-2021-27065 to install China Chopper, which launched PowerShell to download the botnet payload. Targets included banking, insurance, retail and construction organizations across the United States, South America, Europe and East Asia.
ESET identified at least 10 APT groups exploiting the Exchange vulnerabilities and detected webshells on more than 5,000 email servers across more than 115 countries. Its investigation also found overlapping targeting and webshells accessed by multiple groups, suggesting some attackers may have hijacked existing footholds.
ESET identified an activity cluster targeting approximately 650 servers with a first-stage webshell named RedirSuiteServerProxy. Targets were predominantly in Germany, other European countries, the United Kingdom and the United States.
An unattributed activity cluster compromised email servers at an East Asian software development company and a Middle Eastern real estate company. The attackers deployed ShadowPad, which supports remote control, keylogging and data exfiltration.
After patches were released, attackers used webshells to install IIS backdoors on four email servers in Asia and South America.
After patch release and public disclosure, CactusPete compromised email servers at an Eastern European procurement company and a cybersecurity consulting company. The attacks deployed a ShadowPad loader and a Bisonal remote-access trojan variant.
ESET identified a pre-patch activity cluster named Websiic targeting seven email servers. Victims included Asian IT, telecommunications and engineering companies and an Eastern European government body.
Calypso compromised government email servers in the Middle East and South America before patches were released, then targeted government entities and private companies across Africa, Asia and Europe. The group deployed a PlugX variant and the Whitebird backdoor using DLL search-order hijacking.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
threatpost.com
Open sourcesocprime.com
Open sourcethreatpost.com
Open sourcereliaquest.com
Open sourcecyber.gc.ca
Open sourcedomaintools.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.