Skip to main content
Skip to main content
30 entries found. Displaying page 1 of 2.
Updated on Jun 29, 2018
Alert level: severe
Updated on Sep 20, 2011
Alert level: severe
Updated on Oct 12, 2011
Alert level: severe
Updated on Oct 02, 2013
Alert level: severe
Updated on Jun 16, 2014
Alert level: severe
Updated on Apr 16, 2015
Alert level: severe
Updated on Aug 03, 2022
Alert level: severe
Updated on Mar 09, 2023
Alert level: severe
Updated on May 30, 2017
Alert level: severe
Updated on Feb 06, 2020
Alert level: severe
Updated on Mar 11, 2021
Alert level: severe
Updated on Aug 02, 2022

Microsoft Defender Antivirus detects and removes this threat. 

This backdoor is associated with attacks that exploit vulnerabilities affecting Microsoft Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019. The first one, identified as CVE-2022-41040, is a server-side request forgery (SSRF) vulnerability, while the second one, identified as CVE-2022-41082, allows remote code execution (RCE) when Exchange PowerShell is accessible to the attacker. 

This threat is leveraged by attackers to maintain access and persistence on a target device. 

Alert level: severe
Updated on Aug 11, 2022
Alert level: severe
Updated on Mar 10, 2021
Alert level: severe
Updated on Dec 02, 2021
Alert level: severe
Updated on Sep 26, 2019
Alert level: severe
Updated on Apr 04, 2024
Alert level: severe
Updated on Jul 06, 2020
Alert level: severe
Updated on Dec 06, 2021
Alert level: severe
Updated on May 20, 2025
Alert level: severe