Webshells Observed in Post-Compromised Exchange Servers  

Original release date: March 25, 2021CISA has added two new Malware Analysis Reports (MARs) to Alert AA21-062A: Mitigate Microsoft Exchange Server Vulnerabilities. Each new MAR (AR21-084A and AR21-084B) identifies a webshell observed in post-compromised Microsoft Exchange Servers. After successful exploiting a Microsoft Exchange Server vulnerability for initial accesses, a malicious cyber actor can upload a webshell to enable remote administration of the affected system. CISA has also updated seven previously released MARs. The updated MARs now include CISA-developed YARA rules to help...