Microsoft disclosed a remote code execution vulnerability in Microsoft Exchange server on March 2, 2021. We have already seen attacks attempting to implant Webshell, obtaiin mailbox information, and conducting XMRig based mining activities, we named it Tripleone. We customized our Anglerfish honeypot to simulate and deploy Microsoft Exchange honeypot plug-in on March 3, and soon we started to see a large amount of related data, so far, we have seen attacks. We named the Tripleone attack after the vulnerability.”]
Source: https://blog.netlab.360.com/microsoft-exchange-vulnerability-cve-2021-26855-scan-analysis-3/

