logo

Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities

ID: e94f90b7-c487-523b-9476-c03294540003

STIX ID: report--e94f90b7-c487-523b-9476-c03294540003

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2021-03-02

Date Updated: 2026-05-01

...
...

Volexity reports active attacks against Microsoft Exchange that chain an authentication bypass and an RCE (via Set-OabVirtualDirectory) to access mailboxes and drop webshells (SIMPLESEESHARP, SPORTSBALL and others); attackers then perform credential dumping, lateral movement, and data exfiltration. The report supplies detailed IOCs (targeted OWA/ECP paths, suspicious POST entries, User-Agent strings, attacker IPs), examples of exploit activity in logs, and YARA signatures for webshells, and urges immediate patching or isolation of Exchange servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.