ATT&CKReferencesVolexity Exchange Marauder March 2021

Volexity Exchange Marauder March 2021

Gruzweig, J. et al. (2021, March 2). Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities. Retrieved March 3, 2021.

Open the source

Techniques1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupHAFNIUM

HAFNIUM has used procdump to dump the LSASS process memory.

T1003.003
NTDS
GroupHAFNIUM

HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT).

T1059.001
PowerShell
GroupHAFNIUM

HAFNIUM has used the Exchange Power Shell module Set-OabVirtualDirectoryPowerShell to export mailbox data.

T1098
Account Manipulation
GroupHAFNIUM

HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts.

T1114.002
Remote Email Collection
GroupHAFNIUM

HAFNIUM has used web shells and MSGraph to export mailbox data.

T1136.002
Domain Account
GroupHAFNIUM

HAFNIUM has created domain accounts.

T1190
Exploit Public-Facing Application
GroupHAFNIUM

HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server.

T1218.011
Rundll32
GroupHAFNIUM

HAFNIUM has used rundll32 to load malicious DLLs.

T1505.003
Web Shell
GroupHAFNIUM

HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy.

T1560.001
Archive via Utility
GroupHAFNIUM

HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration.

T1589.002
Email Addresses
GroupHAFNIUM

HAFNIUM has collected e-mail addresses for users they intended to target.

T1590
Gather Victim Network Information
GroupHAFNIUM

HAFNIUM gathered the fully qualified domain names (FQDNs) for targeted Exchange servers in the victim's environment.

T1590.005
IP Addresses
GroupHAFNIUM

HAFNIUM has obtained IP addresses for publicly-accessible Exchange servers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.