logo

The Microsoft Exchange Server Exploit: What Happened Next

ID: acc3f6ba-a5be-526c-80c7-7b11c2eeff5a

STIX ID: report--acc3f6ba-a5be-526c-80c7-7b11c2eeff5a

Feed Name: ReliaQuest Blog

Threat Score
90/100

Date Published: 2021-04-01

Date Updated: 2026-04-29

...
...

This report examines the widespread, active exploitation of four Microsoft Exchange Server zero-day vulnerabilities (ProxyLogon) by a range of actors — initially attributed to the HAFNIUM APT and later adopted by multiple APTs, ransomware operators (DearCry, Black Kingdom), and cryptomining botnets (LemonDuck) — describes PoC disclosures and potential leaks, outlines mitigation actions (patches, Microsoft mitigation tool, detection scripts), and maps observed behaviors to MITRE ATT&CK techniques while urging investigation of potentially compromised systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.