Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitystate-sponsored-espionagewidely-deployed-product-advisorydetection-content-update

Mass Exploitation of Microsoft Exchange Flaws Led to Global Email Server Compromises

Updated 15d agoFirst seen May 25, 202628 sources

Attackers exploited multiple zero-day and later related vulnerabilities in on-premises Microsoft Exchange Server to compromise email systems at tens of thousands of organizations worldwide, including government agencies, banks, universities, defense contractors, law firms, healthcare entities, local governments, and small businesses. Microsoft initially attributed the early activity to the China-linked group Hafnium, while CISA, the FBI, and the White House warned that exploitation quickly spread to many additional state-backed and criminal actors after patches were released. The intrusions affected Exchange 2010, 2013, 2016, and 2019 deployments rather than Exchange Online or Microsoft 365, and enabled attackers to steal emails and address books, dump credentials, install web shells such as China Chopper, move laterally, and in some cases deploy follow-on malware including ransomware.

U.S. and allied governments later formally attributed the campaign to actors affiliated with China’s Ministry of State Security, as CISA said organizations should investigate for compromise dating back to at least January 2021 and assume identity compromise where exploitation was found. Security researchers and incident responders reported thousands of backdoored servers across more than 100 countries, with many systems still unpatched well after disclosure, and warned that patching alone did not remove implanted persistence. Microsoft and CISA released emergency updates, detection and remediation guidance, and tools including Test-ProxyLogon.ps1 and EOMT.ps1, while later research showed Exchange attack chains such as ProxyShell could still be adapted for remote code execution and could evade weak perimeter defenses, reinforcing that rapid patching and thorough incident response were essential.

Share:
Mass Exploitation of Microsoft Exchange Flaws Led to Global Email Server Compromises
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

15 events from the most recent confirmed update back to the earliest known activity.

15 EVENTS
Sep 15, 20215y ago

Microsoft patches additional Exchange flaws later tied to ProxyShell

MDSec said Microsoft patched multiple Exchange Server vulnerabilities in April and May 2021 that became central to ProxyShell exploitation research. These fixes addressed attack paths that could be combined for remote code execution without dropping a web shell.

NSA Meeting Proposal for ProxyShell - MDSec

MDSec publishes ProxyShell and NSA Meeting exploit analysis

On 2021-09-15, MDSec published technical research showing how ProxyShell and the so-called NSA Meeting flaw could be combined to achieve Exchange remote code execution without dropping a web shell. The post also described WAF evasion techniques and argued patching was the only reliable mitigation.

NSA Meeting Proposal for ProxyShell - MDSec
Jul 19, 20215y ago

DOJ announces charges against four Chinese nationals

On 2021-07-19, the Justice Department announced charges against four Chinese nationals accused of working with the MSS in a long-running hacking campaign. The announcement accompanied the coordinated public attribution of the Exchange activity to China.

US blames China for hacks, including Microsoft, opening new front in cyber offensive | CNN Politics

U.S. and allies publicly blame China for Exchange exploitation

On 2021-07-19, the United States and multiple allies formally attributed the mass exploitation of Microsoft Exchange vulnerabilities to actors affiliated with China's Ministry of State Security. CISA updated its advisory the same day to reflect the attribution.

Mitigate Microsoft Exchange Server Vulnerabilities | CISA
Apr 12, 20215y ago

DOJ launches court-authorized cleanup of Exchange web shells

On 2021-04-12, the U.S. Justice Department announced a court-authorized effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities. The action targeted malicious web shells left on compromised servers.

Office of Public Affairs | Justice Department Announces Court-Authorized Effort to Disrupt Exploitation of Microsoft Exchange Server Vulnerabilities | United States Department of Justice
Mar 10, 20215y ago

Dutch researchers find 46,000 Exchange servers still unpatched

BleepingComputer reported that after scanning 250,000 Exchange servers worldwide, the Dutch Institute for Vulnerability Disclosure found 46,000 still unpatched against the heavily exploited flaws. The finding underscored the large remaining attack surface after disclosure.

More hacking groups join Microsoft Exchange attack frenzy

ESET reports many additional APT groups exploiting ProxyLogon

By 2021-03-10, ESET reported that at least 10 APT groups and several unclassified clusters were exploiting the Exchange ProxyLogon vulnerabilities beyond Hafnium. It said web shells had been deployed on more than 5,000 unique servers across over 115 countries based on incomplete telemetry.

More hacking groups join Microsoft Exchange attack frenzy

CISA and FBI issue joint advisory on Exchange compromise

On 2021-03-10, CISA and the FBI released a Joint Cybersecurity Advisory on the Microsoft Exchange Server compromise. The agencies warned the flaws could enable network compromise, data theft, ransomware, or destructive attacks and mapped observed activity to MITRE ATT&CK.

FBI-CISA Joint Advisory on Compromise of Microsoft Exchange Server | CISA
Mar 8, 20215y ago

European Banking Authority discloses Exchange compromise

The European Banking Authority was reported as a victim of the Exchange hack, illustrating that the victim set extended beyond the United States. Reporting also said the scale of compromise was larger than initially estimated.

European Banking Authority hit by Microsoft Exchange hack

Attackers shift to mass scanning and backdooring Exchange servers

Krebs reported that in late February 2021, attackers moved from targeted intrusions to broad mass-scanning and backdooring of vulnerable Microsoft Exchange servers. This marked a major escalation in the scope of exploitation.

A Basic Timeline of the Exchange Mass-Hack - Krebs on Security

Researchers identify and report Exchange zero-days and exploitation

Krebs reported that researchers from DEVCOR, Volexity, and Dubex identified or reported aspects of the Exchange flaws and active exploitation between early January and early February 2021. These findings showed Microsoft and security firms were aware of the issue weeks before emergency patches were released.

A Basic Timeline of the Exchange Mass-Hack - Krebs on Security
Mar 3, 20215y ago

Volexity observes suspicious Exchange data theft activity

Microsoft said Volexity helped detect the intrusions after observing unusually large data transfers tied to Exchange compromises in late January. This observation became an early indicator of the campaign exploiting previously unknown Exchange flaws.

Microsoft: China-based hackers found bug to target US firms | AP News
Mar 2, 20215y ago

Microsoft publicly attributes initial exploitation to Hafnium

Microsoft said the initial exploitation was conducted by Hafnium, a suspected China-linked state-sponsored espionage group targeting U.S.-based organizations. The attribution framed the campaign as a nation-state intrusion focused on email theft and persistent access.

Microsoft says China-backed hackers are exploiting Exchange zero-days | TechCrunch

Microsoft issues defense-in-depth patch for Exchange 2010

Krebs reported that when Microsoft patched the four zero-day flaws, it also issued a defense-in-depth patch for unsupported Exchange Server 2010. This extended mitigation guidance beyond the fully supported Exchange versions.

A Basic Timeline of the Exchange Mass-Hack - Krebs on Security

Microsoft discloses Hafnium Exchange zero-days and releases patches

On 2021-03-02, Microsoft disclosed that Hafnium was exploiting four previously undisclosed vulnerabilities in on-premises Exchange Server and released out-of-band security updates. The company said the flaws could be chained to steal emails and deploy malware, and warned other actors would likely rapidly exploit unpatched systems.

Microsoft says China-backed hackers are exploiting Exchange zero-days | TechCrunch
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

50 LINKEDOpen in app
Affected products
6 linked
Internet Information ServicesExchange OnlineMitmproxyInternet ExplorerSolarwindsMicrosoft Safety Scanner
Organizations
20 linked
Microsoft CorporationVolexitySolarWindsGoogleEsetHuntressTrend MicroAccessDataKrollTechCrunchInternational Business MachinesRed CanaryCrowdStrikeWIREDBroadcomDutch Institute for Vulnerability DisclosureBloombergDubexDEVCORBelkasoft
Breaches
4 linked
ORGANIZATIONSRUNNINGVULNERABLEMICROSOFTEXCHANGEEMAILSERVERS-2021-03EUROPEANBANKINGAUTHORITY-2021-03CITYOFPRAGUE-2021-03SOLARWINDS-2021-03
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Mass Exploitation of Microsoft Exchange Flaws Led to Global Email Server Compromises | Mallory