Category: ProxyShell

Providing Solutions

Active Adversary Playbook 2022 Insights: Web Shells

Public proofs-of-concept of web shell exploits coincide with major spikes in attacks.

The Active Adversary Playbook 2022

Cyberattacker behaviors, tactics and tools seen on the frontline of incident response during 2021

Conti and Karma actors attack healthcare provider at same time through ProxyShell exploits

An unpatched Microsoft Exchange Server let both ransomware actors in; Karma just stole data, while Conti encrypted.

Vulnerable Exchange server hit by Squirrelwaffle and financial fraud

While Squirrelwaffle leveraged Exchange to spread malspam through hijacked email threads, one thread was spirited away by attackers to trick the target into a money transfer