Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
ProxyLogon
Vulnerability
Threat entity extracted from intelligence sources
Entities
›
vulnerability
›
ProxyLogon
Frequency
13
occurrences
First Seen
October 29, 2025
Last Seen
September 2, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Exploited By
Salt Typhoon
APT41
ToddyCat
Volt Typhoon
Silk Typhoon
Shadow-Earth-054
Shadow-Earth-053
Hafnium
GhostEmperor
FamousSparrow
Associated Malware
ShadowPad
Cobalt Strike
GodZilla
NoodleRat
React2Shell
SharkLoader
Gaslight
SparrowDoor
Tools Used
Evil-CreateDump
AnyDesk
RingQ
Mdync.exe
Mimikatz
MinHook
Newdcsync
Pillager
Related CVEs
CVE-2026-1731
CVE-2026-31431
CVE-2026-42897
MITRE Techniques
T1505.003 - Web Shell
T1190 - Exploit Public-Facing Application
T1003 - OS Credential Dumping
T1021 - Remote Services
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1055 - Process Injection
T1059.001 - PowerShell
Campaigns
StrikeShark
ProxyLogon campaign
Affected Platforms
Microsoft Exchange
Windows
Microsoft Exchange Server
Exchange Server
F5 Big-ip
GeoServer
Regions
Taiwan
Colombia
India
Indonesia
Lebanon
Sectors Affected
Government
Technology
Transportation
Healthcare
Telecommunications
Defense
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
4
IA
Initial Access
T1190 - Exploit Public-Facing Application
T1133 - External Remote Services
T1078 - Valid Accounts
T1566.002 - Spearphishing Link
3
EX
Execution
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1059.001 - PowerShell
4
PE
Persistence
T1505.003 - Web Shell
T1574 - Hijack Execution Flow
T1543.003 - Windows Service
T1547 - Boot Or Logon Autostart Execution
1
PE
Priv Esc
T1055 - Process Injection
2
DE
Defense Evasion
T1036 - Masquerading
T1112 - Modify Registry
1
CA
Cred Access
T1003 - OS Credential Dumping
-
DI
Discovery
No techniques detected
1
LM
Lateral Mov
T1021 - Remote Services
-
CO
Collection
No techniques detected
1
C2
C2
T1071 - Application Layer Protocol
-
EX
Exfil
No techniques detected
-
IM
Impact
No techniques detected
18
techniques detected across
8
tactics
Related Clusters (12)
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits
Sep 2
·
7 sources
81
SHADOW-EARTH-053 Exploits Microsoft Exchange Vulnerabilities in Asia
May 5
·
2 sources
81
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
May 13
·
10 sources
76
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Apr 2
·
381 sources
73
StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike
Jun 25
·
14 sources
72
Active Exploitation of CVE-2026-42897 in Microsoft Exchange Server
May 15
·
39 sources
70
Congressional Budget Office Hacked, Suspected Foreign Involvement
Nov 7
·
8 sources
44
ToddyCat Malware Targets Microsoft Exchange Servers via ProxyLogon Vulnerability
Jan 7
·
3 sources
32
CISA's KEV Catalog Sees 20% Increase in Vulnerabilities Amid Underreporting Concerns
Jan 5
·
6 sources
30
Congressional Budget Office Hacked by Suspected Foreign Actor
Nov 11
·
20 sources
11
92% of Exchange Servers in Germany Running Out-of-Support Software
Oct 29
·
2 sources
11
Majority of German Exchange Servers Running Out-of-Support Software
Oct 29
·
2 sources
5
Prev
1 / 3
Next
Related Articles (13)
Weekly Threat Bulletin – September 2nd, 2026
F5
·
Sep 2
StrikeShark Campaign Uses New SharkLoader Malware to Deploy Cobalt Strike Beacon
Gbhackers
·
Jun 25
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
Securelist
·
Jun 24
Microsoft warns of Exchange zero
Bleepingcomputer
·
May 15
You Will Always Remember This As The Day You Finally Caught Famoussparrow
www.welivesecurity.com
·
May 13
SHADOW-EARTH-053 Targets Exchange Servers in Asia
Socprime
·
May 5
Chinese spy group caught lurking in Poland, Asia networks
Theregister
·
Apr 30
What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia
Theregister
·
Apr 30
ToddyCat Malware Compromises Microsoft Exchange Servers using ProxyLogon Vulnerability
Cybersecuritynews
·
Jan 7
ToddyCat Malware Exploits ProxyLogon to Compromise Microsoft Exchange Servers
Gbhackers
·
Jan 7
CISOs should fear unpatched vulnerabilities more than zero days
Techmonitor.Ai
·
Nov 19
U.S. Congressional Budget Office hit by suspected foreign cyberattack
Bleepingcomputer
·
Nov 7
9 in 10 Exchange servers in Germany still running out-of-support software
Theregister
·
Oct 29
Prev
1 / 3
Next
Related Entities
Salt Typhoon
APT41
ToddyCat
Volt Typhoon
Silk Typhoon
Shadow-Earth-054
Shadow-Earth-053
Hafnium
GhostEmperor
FamousSparrow
Earth Estries
Earth Alux