Trend Micro says threat actors are exploiting ProxyLogon and ProxyShell exploits in unpatched Microsoft Exchange Servers as part of an ongoing spam campaign. The attacks are believed to have commenced in mid-September 2021 via laced Microsoft Office documents. The attack chain involves rogue email messages containing a link that, when clicked, drops a Microsoft Excel or Word file. Opening the document, in turn, prompts the recipient to enable macros, ultimately leading to the download and execution of the SQUIRRELWAFFLE malware loader.”]
Source: https://thehackernews.com/2021/11/hackers-exploiting-proxylogon-and.html

