Skip to content
Zero-dayResolved

Microsoft Exchange ProxyLogon (Hafnium)

China-linked group Hafnium chained four Exchange Server zero-days (ProxyLogon) to plant web shells and steal email; after Microsoft's emergency patch, mass exploitation by multiple groups compromised an estimated 60,000+ organisations worldwide.

Victim
Microsoft Exchange Server on-premises customers (global)
users
60.0K
CVECVE-2021-26855CVE-2021-26857CVE-2021-26858CVE-2021-27065

On 2 March 2021, Microsoft released emergency out-of-band patches for four previously unknown vulnerabilities in on-premises Exchange Server and attributed their active exploitation to a China state-sponsored group it named Hafnium. The vulnerability chain β€” collectively known as ProxyLogon β€” let an unauthenticated attacker take full control of an Internet-facing Exchange server, read every mailbox, and plant a persistent backdoor.

The vulnerabilities

ProxyLogon was an exploit chain across four CVEs:

  • CVE-2021-26855 β€” a server-side request forgery (SSRF) flaw allowing an unauthenticated attacker to send crafted requests and authenticate as the Exchange server. This was the keystone.
  • CVE-2021-26857 β€” an insecure deserialization flaw in the Unified Messaging service enabling code execution as SYSTEM.
  • CVE-2021-26858 and CVE-2021-27065 β€” post-authentication arbitrary file-write flaws that, combined with the SSRF, let attackers write a web shell anywhere on the server.

Chained together, these turned a reachable Exchange server into a fully attacker-controlled system requiring no valid credentials.

What happened

Hafnium operators exploited the chain to drop ASP-based web shells (such as the widely-tracked "China Chopper" variants), then used that foothold to dump LSASS memory for credentials, export mailboxes, and compress data with 7-Zip for exfiltration. Microsoft characterised the initial Hafnium activity as limited and targeted, focused on U.S. defense contractors, law firms, higher-education institutions, infectious-disease researchers, and think tanks.

The disaster came after disclosure. Once the patch and indicators were public, at least ten distinct threat groups reverse-engineered the fix and launched indiscriminate mass scanning, racing to compromise unpatched servers before administrators could act. Within days an estimated 60,000+ organisations worldwide were compromised, many left with persistent web shells even after patching, because the patch closed the hole but did not remove backdoors already planted.

Response

  • CISA issued Emergency Directive 21-02 on 3 March, ordering federal agencies to patch or disconnect affected servers.
  • Microsoft released a one-click mitigation tool and a safety scanner to help smaller organisations.
  • On 13 April 2021, the U.S. DOJ disclosed a court-authorised FBI operation that proactively removed web shells from hundreds of compromised U.S. servers β€” a notable instance of law enforcement remediating private systems directly.
  • The DearCry ransomware family began exploiting the same flaws within days, turning espionage infrastructure into a ransomware vector.

Why it matters

ProxyLogon is the defining mass-exploitation event of 2021 and a textbook study of patch-gap dynamics: the window between public disclosure and patch deployment became a feeding frenzy in which the very information meant to protect defenders armed dozens of attackers. It hardened industry consensus that internet-facing mail infrastructure is a top-tier target, accelerated migration from on-premises Exchange to managed cloud, and reinforced that patching alone is insufficient β€” once a server is breached, defenders must hunt for and evict the persistence the attacker has already established.

Timeline

  1. Researchers at DEVCORE discover the ProxyLogon SSRF chain (CVE-2021-26855) and begin coordinated disclosure to Microsoft.

  2. DEVCORE and, independently, Volexity report active exploitation of Exchange zero-days to Microsoft.

  3. Hafnium and other actors escalate exploitation, scanning and compromising Internet-facing Exchange servers ahead of a patch.

  4. Microsoft releases emergency out-of-band patches for the four CVEs and publicly attributes the campaign to the China-based Hafnium group.

  5. CISA issues Emergency Directive 21-02 ordering U.S. federal agencies to patch or disconnect affected Exchange servers.

  6. Mass exploitation by 10+ threat groups follows public disclosure; an estimated 60,000+ organisations worldwide are compromised, many with persistent web shells.

  7. The DearCry ransomware family is observed exploiting the same Exchange vulnerabilities.

  8. The U.S. DOJ announces a court-authorised FBI operation to remove malicious web shells from hundreds of compromised U.S. Exchange servers.

Sources

  1. microsoft.comhttps://www.microsoft.com/en-us/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
  2. cisa.govhttps://www.cisa.gov/news-events/cybersecurity-advisories/aa21-062a
  3. msrc.microsoft.comhttps://msrc.microsoft.com/blog/2021/03/multiple-security-updates-released-for-exchange-server/
  4. unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/microsoft-exchange-server-attack-timeline/

Related incidents

Zero-dayOngoing

SonicWall warns of two SMA 1000 zero-days exploited in the wild (CVE-2026-15409, CVE-2026-15410)

SonicWall issued an urgent advisory after attackers were caught chaining two zero-day flaws in its SMA 1000 secure remote-access appliances β€” an unauthenticated SSRF rated CVSS 10.0 and a post-authentication command-injection bug β€” with Rapid7 having observed the pair exploited in tandem against internet-facing devices before any patch existed.

Victim
SonicWall SMA 1000
Zero-dayContained

NAIC confirms data breach after Oracle PeopleSoft zero-day exploited by ShinyHunters

The National Association of Insurance Commissioners disclosed on 23 June 2026 that attackers exploited an Oracle PeopleSoft zero-day to access part of its environment, and by 25 June the extortion group ShinyHunters had published the stolen data online, claiming more than 3.1 terabytes.

Victim
National Association of Insurance Commissioners (NAIC)