Threats Feed|APT35|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date18/08/2023

APT35's Exploitation of Microsoft Exchange: Targeting Europe, Middle East, and North America

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Vulnerability Exploitation,Backdoor,Spear Phishing
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

AttackIQ's August 2023 report profiles APT35 (also known as Charming Kitten and Phosphorus), an Iranian state-sponsored espionage group active since at least 2014. The report presents an attack graph emulating APT35's December 2021 exploitation of Microsoft Exchange ProxyShell vulnerabilities — CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 — to gain initial access across targets in Europe, the Middle East, and North America. The documented attack chain begins with web shell deployment on the compromised Exchange server, followed by scheduled task persistence, disabling of Microsoft Defender via registry modification, WDigest authentication enablement for plaintext credential capture, LSASS memory dumping via rundll32.exe and comsvcs.dll, and data exfiltration via HTTP POST requests. The group also created local accounts added to the Administrators and Remote Desktop Users groups and opened port 3389 (RDP) through Windows Firewall for persistent remote access. APT35 targets government entities, academic institutions, media organizations, defense, energy, engineering, business services, and telecommunications sectors, with a particular focus on the United States and Middle East.

Detected Targets

TypeDescriptionConfidence
SectorDefense
None
Verified
SectorGovernment Agencies and Services
None
Verified
SectorTelecommunication
None
Verified
SectorUniversity
None
Verified
SectorUtilities
None
Verified
RegionMiddle East Countries
Verified
RegionEuropean Countries
Verified

Extracted IOCs

  • kcp53.msupdate[.]us
  • tcp443.msupdate[.]us
  • 1a5ad24a6880eea807078375d6461f58
  • 5f098b55f94f5a448ca28904a57c0e58
  • 9a3703f9c532ae2ec3025840fa449d4e
  • b2fde6dc7bd1e04ce601f57805de415b
  • cacb64bdf648444e66c82f5ce61caf4b
  • d2f4647a3749d30a35d5a8faff41765e
  • f0be699c8aafc41b25a8fc0974cc4582
  • 0f676bc786db3c44cac4d2d22070fb514b4cb64c
  • 27102b416ef5df186bd8b35190c2a4cc4e2fbf37
  • 3a6431169073d61748829c31a9da29123dd61da8
  • 4d243969b54b9b80c1d26e0801a6e7e46d2ef03e
  • 6bae2d45bbd8c4b0a59ba08892692fe86e596154
  • 8ece87086e8b5aba0d1cc4ec3804bf74e0b45bee
  • da2470c3990ea0862a79149c6036388498da83cd
  • 1604e69d17c0f26182a3e3ff65694a49450aafd56a7e8b21697a932409dfd81e
  • 559d4abe3a6f6c93fc9eae24672a49781af140c43d491a757c8e975507b4032e
  • 668ec78916bab79e707dc99fdecfa10f3c87ee36d4dee6e3502d1f5663a428a0
  • 7b5fbbd90eab5bee6f3c25aa3c2762104e219f96501ad6a4463e25e6001eb00b
  • 84f77fc4281ebf94ab4897a48aa5dd7092cc0b7c78235965637eeef0908fb6c7
  • c5aae30675cc1fd83fd25330cec245af744b878a8f86626d98b8e7fcd3e970f8
  • 107[.]173.231.114
  • 148[.]251.71.182
download

Tip: 24 related IOCs (2 IP, 2 domain, 0 URL, 0 email, 20 file hash) to this threat have been found.

Overlaps

Cobalt MirageUnveiling the Actors behind COBALT MIRAGE: A Ransomware Incident Analysis

Source: Secureworks - September 2022

Detection (one case): 148[.]251.71.182

UnclassifiedIranian Cyber Actors Target Western Nations in Ransom and Extortion Campaigns

Source: CISA - September 2022

Detection (16 cases): 107[.]173.231.114, 148[.]251.71.182, 0f676bc786db3c44cac4d2d22070fb514b4cb64c, 1604e69d17c0f26182a3e3ff65694a49450aafd56a7e8b21697a932409dfd81e, 27102b416ef5df186bd8b35190c2a4cc4e2fbf37, 3a6431169073d61748829c31a9da29123dd61da8, 559d4abe3a6f6c93fc9eae24672a49781af140c43d491a757c8e975507b4032e, 5f098b55f94f5a448ca28904a57c0e58, 668ec78916bab79e707dc99fdecfa10f3c87ee36d4dee6e3502d1f5663a428a0, 6bae2d45bbd8c4b0a59ba08892692fe86e596154, 7b5fbbd90eab5bee6f3c25aa3c2762104e219f96501ad6a4463e25e6001eb00b, 8ece87086e8b5aba0d1cc4ec3804bf74e0b45bee, 9a3703f9c532ae2ec3025840fa449d4e, cacb64bdf648444e66c82f5ce61caf4b, d2f4647a3749d30a35d5a8faff41765e, f0be699c8aafc41b25a8fc0974cc4582

PhosphorusStealth in the System: PHOSPHORUS Exploits Exchange Server in Infrastructure Sector Attack

Source: Deep Instinct - June 2022

Detection (six cases): 107[.]173.231.114, 148[.]251.71.182, 1604e69d17c0f26182a3e3ff65694a49450aafd56a7e8b21697a932409dfd81e, 7b5fbbd90eab5bee6f3c25aa3c2762104e219f96501ad6a4463e25e6001eb00b, kcp53.msupdate[.]us, tcp443.msupdate[.]us

Cobalt MirageCOBALT MIRAGE's Exploits: Targeting Israeli and Western Organizations

Source: Secureworks - May 2022

Detection (four cases): 107[.]173.231.114, 27102b416ef5df186bd8b35190c2a4cc4e2fbf37, 5f098b55f94f5a448ca28904a57c0e58, 668ec78916bab79e707dc99fdecfa10f3c87ee36d4dee6e3502d1f5663a428a0

PhosphorusPowerLess Backdoor: Analyzing the Phosphorus Group's Cyber Espionage Tool

Source: Cybereason - February 2022

Detection (one case): 148[.]251.71.182

APT35CharmPower: APT35's Modular Toolset Exploits Log4j Vulnerability

Source: Check Point - January 2022

Detection (one case): 148[.]251.71.182

PhosphorusIranian-backed PHOSPHORUS Exploits Microsoft Exchange Vulnerabilities for Data Encryption

Source: The DFIR Report - November 2021

Detection (one case): 148[.]251.71.182

PhosphorusAutomated Scripts Used in Microsoft Exchange ProxyShell Attack By PHOSPHORUS

Source: The Dfir Report - March 2021

Detection (24 cases): 107[.]173.231.114, 148[.]251.71.182, 0f676bc786db3c44cac4d2d22070fb514b4cb64c, 1604e69d17c0f26182a3e3ff65694a49450aafd56a7e8b21697a932409dfd81e, 1a5ad24a6880eea807078375d6461f58, 27102b416ef5df186bd8b35190c2a4cc4e2fbf37, 3a6431169073d61748829c31a9da29123dd61da8, 4d243969b54b9b80c1d26e0801a6e7e46d2ef03e, 559d4abe3a6f6c93fc9eae24672a49781af140c43d491a757c8e975507b4032e, 5f098b55f94f5a448ca28904a57c0e58, 668ec78916bab79e707dc99fdecfa10f3c87ee36d4dee6e3502d1f5663a428a0, 6bae2d45bbd8c4b0a59ba08892692fe86e596154, 7b5fbbd90eab5bee6f3c25aa3c2762104e219f96501ad6a4463e25e6001eb00b, 84f77fc4281ebf94ab4897a48aa5dd7092cc0b7c78235965637eeef0908fb6c7, 8ece87086e8b5aba0d1cc4ec3804bf74e0b45bee, 9a3703f9c532ae2ec3025840fa449d4e, b2fde6dc7bd1e04ce601f57805de415b, c5aae30675cc1fd83fd25330cec245af744b878a8f86626d98b8e7fcd3e970f8, cacb64bdf648444e66c82f5ce61caf4b, d2f4647a3749d30a35d5a8faff41765e, da2470c3990ea0862a79149c6036388498da83cd, f0be699c8aafc41b25a8fc0974cc4582, kcp53.msupdate[.]us, tcp443.msupdate[.]us

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions About APT35's Microsoft Exchange ProxyShell Campaign

In December 2021, APT35 (also known as Charming Kitten and Phosphorus) exploited three Microsoft Exchange vulnerabilities — collectively known as ProxyShell — to break into organizations across Europe, the Middle East, and North America. Once inside, the group deployed web shells, disabled security tools, created hidden persistence mechanisms, dumped credentials from system memory, and exfiltrated the results to attacker-controlled servers.

The attacks are attributed to APT35, an Iranian state-sponsored cyber-espionage group also tracked as Charming Kitten and Phosphorus. The group has been active since at least 2014 and is assessed to operate in support of Iran's strategic intelligence priorities. Their campaigns consistently target government, military, academic, and energy sector organizations in countries considered rivals or adversaries of Iran.

The primary goals were credential theft, network reconnaissance, and persistent access to strategic targets. APT35 disabled endpoint defenses, forced plaintext password storage via WDigest, dumped authentication credentials from memory, and set up multiple re-entry routes through scheduled tasks and RDP-enabled local accounts. The intelligence gathered supports Iran's long-term geopolitical and military interests.

The campaign targeted organizations in Europe, the Middle East, and North America. Any organization running an unpatched, internet-facing Microsoft Exchange server was at risk. APT35's broader targeting history shows a particular focus on the United States and Middle Eastern countries, spanning government, military, academic, energy, and telecommunications institutions.

APT35 primarily targets government entities, academic institutions, military and defense organizations, energy companies, media outlets, engineering firms, and telecommunications providers. The group has a documented history of targeting individuals and institutions in the United States, Israel, and Middle Eastern countries — particularly those with access to sensitive policy, scientific, or intelligence information.

The attack began by exploiting ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) in internet-facing Exchange servers to deploy web shells. From those shells, APT35 downloaded batch files and XML-based scheduled tasks for persistence, then disabled Microsoft Defender by modifying Windows registry keys. They created a local account with administrator privileges, opened port 3389 via the firewall for RDP access, disabled LSA protection, and enabled WDigest so Windows would store future login credentials in plaintext. Finally, they used rundll32.exe with comsvcs.dll to dump LSASS memory containing credential hashes, and sent the dump to their C2 infrastructure via HTTP POST.

Organizations running Microsoft Exchange are central to email communications and often hold sensitive data, making them high-value targets. Government and defense organizations in countries opposed to Iran's interests are of direct intelligence value. Academic institutions and think tanks frequently hold unpublished research, policy analysis, and sensitive personal contacts. The ProxyShell vulnerabilities allowed APT35 to gain access without needing to trick an individual employee — any unpatched public-facing Exchange server was a potential entry point.

Apply all three ProxyShell patches (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) immediately and scan Exchange servers for web shells in OWA and authentication directories. Enable Windows Credential Guard and LSA Protection (RunAsPPL) to block LSASS dumping. Monitor registry changes under Windows Defender policy keys, alert on local account group membership changes (especially additions to Administrators or Remote Desktop Users), and watch for netsh firewall rules opening port 3389. Block outbound HTTP POST traffic from Exchange servers to unknown external hosts, and flag connections to lookalike Microsoft update domains matching the msupdate[.]us pattern.

About Affiliation
APT35
APT35 is Mandiant's designation for the Iranian state-sponsored threat actor widely tracked as Charming Kitten, linked to the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2014, the group targets journalists, academics, human rights activists, think tank researchers, and government officials using elaborate spear phishing campaigns. APT35 is known for impersonating major media outlets and sending credential harvesting links via email and SMS. The group also exploits N-day vulnerabilities in enterprise applications such as ProxyShell and Log4Shell to gain initial access to high-value targets.
View APT35's Insights