Microsoft says Iranian state-sponsored hackers are actively exploiting Zerologon, a Windows vulnerability in the Netlogon protocol, in hacking campaigns
Microsoft links back the attacks to an Iranian hacker group known as Mercury, or MuddyWater. — Microsoft said on Monday …
Context & Ripple Effects
Microsoft's threat-intelligence operation has become the recurring public alarm for Iranian cyber activity: in 2019 it named Phosphorus attempting to hack 241 accounts tied to a 2020 presidential campaign, and this week it attributes active Zerologon exploitation to another Iran-linked actor, Mercury (MuddyWater). The throughline is that state-sponsored groups keep weaponizing vulnerabilities in Microsoft's own Windows stack.
The precedent matters: in 2018 Microsoft patched a Windows privilege-escalation zero-day after Kaspersky Lab spotted multiple espionage groups exploiting it, and in late 2021 Microsoft and Mandiant flagged state-backed groups from China, Iran, North Korea, and Turkey exploiting Log4j. Zerologon fits that sequence — a protocol-level Windows flaw being worked by a named national actor while defenders race to patch.
First-order effects
- Organizations running unpatched Windows domain controllers are the immediate targets, since Zerologon lives in the Netlogon protocol that authenticates machines on corporate networks.
- Microsoft's attribution puts pressure on IT teams to treat the Netlogon patch as urgent rather than routine, and hands incident responders a concrete adversary profile (Mercury/MuddyWater) to hunt for.
Second-order effects
- Once one state group proves out a Windows protocol exploit, others historically follow — the 2018 zero-day was used by several espionage groups at once — so security vendors will see demand spike for Netlogon-specific detection and hardening.
- Rival intelligence agencies' targeting choices get benchmarked against Microsoft's disclosures, making the vendor's attribution reports a de facto input into other governments' threat warnings.
Third-order effects
- If the pattern holds — named state groups adopting each significant Windows or ecosystem flaw shortly after disclosure — patching cadence stops being an IT hygiene metric and becomes a national-security exposure, with regulators likely to lean harder on rapid-deployment mandates.
- Microsoft's threat-intelligence unit consolidates a structural role: the company that owns the attacked software is also the primary source of attribution, concentrating both defensive guidance and geopolitical naming power in one vendor.
The trend: State-sponsored hacking groups are industrializing the exploitation of newly disclosed infrastructure vulnerabilities, with Microsoft's own threat-intelligence reports serving as the sector's early-warning system.