logo

HAFNIUM__2021__Operation_Exchange_Marauder_Active_Exploitation_of_Multiple_Zero-Day_Microsoft_Exchange_Vulnerabilities_Volexity.pdf

ID: d85f3085-4576-4f1a-bd72-90a6b490e932

STIX ID: report--d85f3085-4576-4f1a-bd72-90a6b490e932

Threat Score

92/100

Uploaded: 2026-08-15

Published Date: 2021-03-12

Last Modified Date: 2021-03-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Volexity observed active exploitation of multiple Microsoft Exchange zero-day vulnerabilities (including pre-auth SSRF CVE-2021-26855 and chained RCE CVE-2021-27065) beginning in early January 2021; attackers bypassed authentication to read mailboxes, wrote webshells (SIMPLESEESHARP, SPORTSBALL, China Chopper variants), dumped credentials/NTDS.DIT, created accounts, and moved laterally. The report provides exploit details, POST payload examples, IIS/ECP log indicators, user-agent strings, attacker IP addresses, and YARA signatures, and urges immediate patching or disabling external Exchange access.