logo

Rapid Response: Mass Exploitation of On-Prem Exchange Servers

ID: 0c1cd81b-561c-56ce-ae81-cd0ee6567893

STIX ID: report--0c1cd81b-561c-56ce-ae81-cd0ee6567893

Feed Name: Huntress Blog

Threat Score
92/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

Huntress details widespread, active exploitation of on-premises Microsoft Exchange Server zero-day vulnerabilities (March–April 2021), reporting thousands of vulnerable servers and hundreds of observed webshells (China Chopper). The report documents exploitation chains and multi-stage PowerShell payloads that establish persistence, fetch additional payloads, and deploy post-exploitation tools (including Mimikatz and Cobalt Strike), provides IOCs and patch/verification guidance, and urges immediate patching and active hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.