Iranian-backed PHOSPHORUS Exploits Microsoft Exchange Vulnerabilities for Data Encryption
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Vulnerability Exploitation,Backdoor,Ransomware
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
The DFIR Report's November 2021 case study documents a PHOSPHORUS (APT35/Charming Kitten) intrusion in late September 2021 in which the attacker exploited the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) on an internet-facing Microsoft Exchange server. Over 42 hours, three web shells were deployed in OWA directories. The attacker used PowerShell and cmd.exe via web shells to run Exchange discovery cmdlets (Get-Mailbox, Get-ExchangeServer), then enabled the built-in DefaultAccount, set its password to P@ssw0rd, and added it to Administrators and Remote Desktop Users groups. Plink was used to establish an SSH tunnel to 148.251.71[.]182 (tcp.symantecserver.co), exposing RDP externally. LSASS was dumped via Task Manager. Fast Reverse Proxy (FRP, renamed to dllhost.exe) was deployed for persistent RDP proxying via a scheduled task named CacheTask. Using stolen domain admin credentials, the actors performed internal port scanning with KPortScan 3.0, moved laterally to backup systems and domain controllers via RDP, and deployed Impacket's wmiexec on one domain controller. The final impact was domain-wide encryption: BitLocker on servers (via setup.bat) and DiskCryptor on workstations via dcrypt.exe, with a ransom note requesting 8,000 USD left on an unencrypted domain controller. No data exfiltration or Cobalt Strike was used — notably rare for a ransomware intrusion of this scale.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Information Technology None | Verified |
Exploited Vulnerabilities
Extracted IOCs
- tcp.symantecserver[.]co
- 31f05b4ee52f0512c96d0cc6f158e083
- 3375fe67827671e121d049f9aabefc3e
- 34623dc70d274157dbc6e08b21154a3f
- 7c2b567b659246d2b278da500daa9abe
- d4a55e486f5e28168bc4554cffa64ea0
- 3664e6e27fb2784f44f6dba6105ac8b90793032a
- 49c222afbe9c610fa75ffbbfb454728e608c8b57
- 83d21bb502b73016ec0ad7d6c725d71aaffa0f6d
- e5286dbd0a54a110b39eb1e3e7015d82f316132e
- ef949770ae46bb58918b0fe127bec0ec300b18a9
- 02ac3a4f1cfb2723c20f3c7678b62c340c7974b95f8d9320941641d5c6fd2fee
- 60d22223625c86d7f3deb20f41aec40bc8e1df3ab02cf379d95554df05edf55c
- 98ccde0e1a5e6c7071623b8b294df53d8e750ff2fa22070b19a88faeaa3d32b0
- dc4186dd9b3a4af8565f87a9a799644fce8af25e3ee8777d90ae660d48497a04
- e3eac25c3beb77ffed609c53b447a81ec8a0e20fb94a6442a51d72ca9e6f7cd2
- 148[.]251.71.182
- 18[.]221.115.241
- 198[.]144.189.74
- 217[.]23.5.42
- 37[.]139.3.208
- 86[.]57.38.156
Tip: 22 related IOCs (6 IP, 1 domain, 0 URL, 0 email, 15 file hash) to this threat have been found.
Overlaps
Source: ESET - September 2023
Detection (one case): 198[.]144.189.74
Source: AttackIQ - August 2023
Detection (one case): 148[.]251.71.182
Source: Secureworks - September 2022
Detection (one case): 148[.]251.71.182
Source: CISA - September 2022
Detection (two cases): 148[.]251.71.182, 198[.]144.189.74
Source: Deep Instinct - June 2022
Detection (three cases): 148[.]251.71.182, 198[.]144.189.74, e3eac25c3beb77ffed609c53b447a81ec8a0e20fb94a6442a51d72ca9e6f7cd2
Source: Cybereason - February 2022
Detection (one case): 148[.]251.71.182
Source: Check Point - January 2022
Detection (one case): 148[.]251.71.182
Source: The Dfir Report - March 2021
Detection (one case): 148[.]251.71.182
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions About PHOSPHORUS's Exchange ProxyShell Ransomware Attack
PHOSPHORUS, an Iranian state-sponsored threat group also known as APT35 and Charming Kitten, exploited the ProxyShell vulnerability chain in a Microsoft Exchange server in late September 2021. Over 42 hours they moved from initial access to domain-wide encryption, using BitLocker on servers and DiskCryptor on workstations. No custom malware or common C2 frameworks were used — the entire attack relied on native Windows tools, open-source utilities, and built-in encryption. A ransom note demanding $8,000 USD was left on an unencrypted domain controller. The DFIR Report published its analysis in November 2021.
The attack is attributed to PHOSPHORUS, an Iranian state-sponsored group also tracked as APT35, Charming Kitten, Mint Sandstorm, and DEV-0270. Microsoft publicly attributed a similar ProxyShell ransomware campaign to PHOSPHORUS at CyberWarCon 2021, the same week The DFIR Report published this case. The group has historically focused on espionage but this campaign demonstrates a documented shift toward financially motivated disruption operations.
The attacks are attributed to PHOSPHORUS, an Iranian state-sponsored group also tracked as APT35, Charming Kitten, DEV-0270, and NemesisKitten. Microsoft published a concurrent analysis linking this specific use of BitLocker and DiskCryptor for ransomware to PHOSPHORUS. The group is assessed to operate on behalf of the Iranian government and is known for combining espionage operations with occasional financially motivated or disruptive attacks.
The attack is attributed to PHOSPHORUS, an Iranian state-sponsored threat group also tracked as APT35, Charming Kitten, DEV-0270, and NemesisKitten. Microsoft assessed this cluster operates on behalf of the Iranian government. The use of ProxyShell for initial access, combined with BitLocker-based encryption for ransom, is consistent with a documented pattern of PHOSPHORUS operations observed across multiple 2021 campaigns where espionage and financially disruptive activity overlapped.
The attack had two apparent goals. The primary impact was destructive — encrypting systems domain-wide to render them inoperable and demand a ransom. But the credential theft (LSASS dump, domain admin account) and Exchange mailbox access suggest intelligence collection may have also occurred before encryption. No data exfiltration was confirmed, but the group had full domain admin access for hours before triggering the encryption payload, leaving open the possibility of quiet data collection prior to the disruptive finale.
The attack had two goals. The primary operational goal was disruption — encrypting every server and workstation in the environment to render them inoperable and demand ransom. But the ransom demand of only $8,000 USD is unusually low for a domain-wide encryption attack, suggesting financial gain may have been secondary to causing operational disruption for strategic or intelligence purposes. PHOSPHORUS's willingness to destroy access to an entire network for a few thousand dollars is consistent with a state-sponsored actor using ransomware as a pressure tactic rather than a profit-focused criminal operation.
The attack had two apparent goals. The first was credential harvesting — LSASS was dumped and domain admin credentials were stolen early in the intrusion, providing broad network access. The second was financial disruption — systems were encrypted domain-wide using BitLocker and DiskCryptor with an $8,000 USD ransom demand. No data was exfiltrated beyond the LSASS dump, which distinguishes this from typical double-extortion ransomware. Researchers noted this may reflect PHOSPHORUS using ransomware as a revenue stream or a tool for covering tracks after espionage activity.
The DFIR Report does not name the victim organization. The attack targeted any organization running an unpatched, internet-facing Microsoft Exchange server — a common configuration across corporate, government, and critical infrastructure environments. ProxyShell was being actively exploited across many sectors in late 2021, and PHOSPHORUS was observed using it against organizations in the Middle East, United States, and Europe during this period.
The specific victim organization is not named in the report. Any organization running an unpatched, internet-facing Microsoft Exchange server (versions 2013, 2016, or 2019) was potentially at risk from this ProxyShell campaign. PHOSPHORUS was observed targeting organizations across the United States, Middle East, and Europe in related ProxyShell campaigns during the same period. The relatively modest ransom demand of $8,000 USD suggests the victim may have been a small-to-mid-size organization rather than a large enterprise.
The specific victim organization is not named in the DFIR Report. The attack targeted any organization running an unpatched, internet-facing Microsoft Exchange server — a widespread condition in September 2021. PHOSPHORUS was observed conducting broad ProxyShell scanning campaigns during this period, meaning the victim pool was large and geographically diverse. Other PHOSPHORUS ProxyShell campaigns from the same period hit organizations across the United States, Europe, the Middle East, and Australia.
No specific industry sector is named in this DFIR Report case study — the victim was identified only by their unpatched Exchange infrastructure. PHOSPHORUS's broader targeting history includes government agencies, defense contractors, NGOs, energy companies, academic institutions, and technology firms, primarily in the United States, Israel, and the Middle East. Any organization running on-premises Exchange Server 2013, 2016, or 2019 without the ProxyShell patches was a potential target during this period.
The attack unfolded over roughly 42 hours across three phases. First, ProxyShell was used to deploy three web shells on the Exchange server, giving SYSTEM-level command execution. Over the next two days, the attackers ran discovery commands, then enabled the built-in DefaultAccount, added it to Administrators and Remote Desktop Users, and used Plink to tunnel RDP over SSH to their server at 148.251.71.182. After dumping LSASS via Task Manager to steal domain admin credentials, they deployed Fast Reverse Proxy (renamed dllhost.exe) for persistent RDP access via a scheduled task. Using the stolen domain admin account, they scanned the internal network with KPortScan, moved to backup systems and domain controllers via RDP, and deployed Impacket wmiexec on at least one domain controller. In the final step, setup.bat enabled BitLocker on servers and DiskCryptor was run on workstations, rendering the entire domain inoperable.
ProxyShell is a chain of three Microsoft Exchange vulnerabilities — CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 — that together allow an unauthenticated attacker to execute arbitrary code with SYSTEM privileges on an Exchange server. The attacker first bypasses access controls via a URL path confusion bug, then elevates privileges on the PowerShell backend, and finally writes arbitrary files by abusing the mailbox export function. In this case the attacker used the export function to write .aspx web shells to OWA directories, giving them a persistent, web-accessible foothold with SYSTEM-level access from day one.
The attack unfolded in three phases over 42 hours. First, the attackers exploited ProxyShell to deploy three web shells on the Exchange server, giving them SYSTEM-level remote command execution. They ran Exchange and network discovery commands over the following two days. On day three, they enabled the built-in DefaultAccount, set a password, and added it to admin groups. They then used Plink to tunnel RDP over SSH to an external attacker server, dumped LSASS via Task Manager to steal domain admin credentials, and deployed Fast Reverse Proxy (disguised as dllhost.exe) for persistent RDP access via a scheduled task. Using the stolen domain admin account, they ran a port scanner, moved laterally to backup servers and domain controllers via RDP, then executed a batch script (setup.bat) that enabled BitLocker on servers and deployed DiskCryptor on workstations — locking every machine in the environment.
This attack is notable because it used almost no custom malware or commercial C2 frameworks — no Cobalt Strike, no custom backdoors. Every tool was either built into Windows (BitLocker, Task Manager, PowerShell, cmd.exe, net.exe) or an open-source utility (Plink, Fast Reverse Proxy, DiskCryptor, wmiexec from Impacket). This living-off-the-land approach makes detection harder because the tools blend with normal administrative activity. It also means PHOSPHORUS could execute the entire attack with minimal operational security risk from malware signatures.
The attack was conducted almost entirely without custom malware. After deploying web shells via ProxyShell, the attacker enabled the built-in DefaultAccount, set a simple password, and added it to admin groups. They then used Plink to establish an SSH tunnel exposing RDP, dropped Fast Reverse Proxy (renamed to dllhost.exe) for persistent RDP access via a scheduled task, dumped LSASS credentials via Task Manager, and scanned the internal network with KPortScan 3.0. Using stolen domain admin credentials they moved laterally to backup servers and domain controllers via RDP. Finally they ran setup.bat on servers to enable BitLocker encryption and executed DiskCryptor on workstations — all over RDP, with no Cobalt Strike or dedicated C2 framework at any stage.
If the blue team had not detected the intrusion before the DefaultAccount was enabled, they would have had roughly 8 hours to respond and evict the attackers before domain-wide encryption began. The 42-hour total time-to-ransom is fast for this type of attack. This underscores the importance of monitoring Exchange servers for web shell deployment immediately after ProxyShell exploitation — that's the earliest detection opportunity. The later activation of DefaultAccount, Plink execution, and LSASS dumping are additional detection points that each still offered a window to contain the breach before the destructive phase.
This attack stands out because no Cobalt Strike or custom malware was used at any stage — rare for a domain-wide ransomware incident of this scale. The actors relied entirely on native Windows tools (PowerShell, cmd, Task Manager, BitLocker), open-source utilities (Plink, Fast Reverse Proxy, DiskCryptor, KPortScan), and the DefaultAccount built into every Windows installation. The ransom demand was also unusually low at $8,000 USD compared to typical big-game ransomware operators, suggesting the financial pressure was secondary to access and disruption. The complete absence of a dedicated C2 framework also makes traditional detection methods based on Cobalt Strike beacons ineffective.
This attack is notable for what it didn't use. The attackers deployed no custom malware, no Cobalt Strike, and no ransomware binary — a rare combination for a domain-wide encryption event. Instead, they relied entirely on ProxyShell web shells for remote execution, native Windows tools (PowerShell, cmd, Task Manager), open-source utilities (Plink, Fast Reverse Proxy, wmiexec), and Windows' own built-in encryption capabilities (BitLocker and DiskCryptor). This "living off the land" approach makes the attack harder to detect with signature-based tools and leaves fewer forensic artifacts. The unusually low $8,000 ransom demand also distinguishes this from typical ransomware-as-a-service operations, suggesting disruption was at least as important as financial gain.
Patch all three ProxyShell CVEs immediately (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and scan Exchange OWA directories for unauthorized .aspx files — including those that appear as PST files on disk. Monitor for DefaultAccount activation and for any account being silently added to Administrators or Remote Desktop Users. Alert on plink.exe running with -R (remote port forwarding) arguments, and on any process named dllhost.exe not originating from System32. Detect KPortScan network scanning and scheduled task creation by unusual parent processes in ProgramData paths. Protect BitLocker activation with GPO controls requiring approval, monitor for BdeHdCfg execution, and maintain tested offline backups that are network-segmented from domain admin credentials — these are the primary target once domain admin access is obtained.
Apply all three ProxyShell patches immediately (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and scan Exchange OWA and authentication directories for unauthorized .aspx files — particularly any PST-disguised files. Monitor for DefaultAccount activation and any account unexpectedly added to Administrators or Remote Desktop Users. Alert on plink.exe running with remote port forwarding arguments (-R flag) and on any process named dllhost.exe not originating from System32. Protect BitLocker via GPO to require approval before enabling encryption without TPM. Maintain tested offline backups isolated from domain admin credentials, and segment backup servers from production domain controllers to limit the blast radius of a stolen domain admin account.
Apply all three ProxyShell patches (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) immediately and scan Exchange OWA directories for unauthorized .aspx files — especially PST-disguised web shells. Alert on DefaultAccount activation and any account added to Administrators or Remote Desktop Users outside normal change management. Monitor for plink.exe with -R (remote port forwarding) arguments and for any dllhost.exe not originating from System32. Detect KPortScan activity and scheduled task creation pointing to ProgramData directories. Protect BitLocker via GPO to require approval before enabling without TPM, and monitor BdeHdCfg execution. Keep offline backups that are network-isolated from domain admin credentials, and ensure backup servers are segmented from production.