www.alstonprivacy.com FBI Disrupts Chinese State-Sponsored Exploitation of Microsoft Exchange Vulnerabilities
Article Content
- •FBI operation targeted Chinese state-sponsored web shells on Microsoft Exchange.
- •Malicious web shells exploited zero-day vulnerabilities, affecting numerous U.S. systems.
- •FBI used remote access techniques to remove malware without user consent.
On April 13, 2021, the FBI executed a novel operation to remove malicious web shells from U.S.-based computers, attributed to the Chinese state-sponsored group Hafnium. These web shells exploited zero-day vulnerabilities in Microsoft Exchange servers, allowing unauthorized access and persistent malware deployment. Despite prior mitigation efforts, hundreds of web shells remained on affected systems. The FBI's warrant permitted remote access to copy and delete these web shells without the owners' knowledge. The operation targeted systems with particularly difficult-to-detect web shells, which had unique file names. The warrant was partially unsealed following the operation's conclusion, allowing the FBI to notify victims through emails and public postings. The FBI's actions represent a significant escalation in countering state-sponsored cyber threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track DearCry, Hafnium and China Chopper in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Escalating Cyber Espionage Threats from China and Russia Cyber espionage has surged, with China and Russia leading state-sponsored attacks on sensitive data. In May 2025, the UK National Cyber Security Center linked breaches of the Electoral Commission to China, while Russian hackers targeted Tajikistan's educational and government sectors. Chinese cyber operations have…
Spring Ring: Coordinated Vishing Campaign Exploits Microsoft Teams Between January and April 2026, a coordinated voice phishing campaign named Spring Ring targeted over 150 employees across more than 10 companies using fake IT support accounts on Microsoft Teams. Attackers registered external Teams tenants with names resembling internal IT departments to gain trust. The campaign…