The DOJ says the FBI performed a court-approved operation to “copy and remove malicious web shells” on hundreds of hacked Exchange servers across the US
The FBI obtained court approval to access vulnerable computers across the United States. — Joseph Cox
VICE Joseph Cox
Context & Ripple Effects
Earlier coverage documented the FBI's use of hacking techniques against more than 1,000 computers, followed by litigation over disclosure of the code used in that operation. That history makes the Exchange action a distinct use of court authority: removing an intrusion tool from victims' systems rather than gathering evidence from suspects.
Later FBI actions against Snake malware used in Russian cyberespionage and the legally authorized disabling of parts of Volt Typhoon's compromised-device operation show a continuing operational role for court-approved technical disruption.
First-order effects
- Owners of the hundreds of affected Exchange servers have malicious web shells removed through the FBI's court-authorized access, reducing the attackers' foothold on those systems.
- The DOJ and FBI establish a documented remedial use of judicial authorization to enter compromised U.S. computers and alter malicious code.
Second-order effects
- The operation gives courts, defenders, and civil-liberties litigants another concrete comparison point to the earlier fight over disclosure of FBI hacking code, shifting scrutiny from investigative access toward government-directed cleanup.
- Future disruption operations can be framed around the same victim-protection rationale used here, alongside the FBI's later malware and compromised-device interventions.
Third-order effects
- If this pattern holds, court-authorized cyber operations will increasingly span both evidence collection and remediation, making the scope and safeguards of government access a recurring legal boundary.
- The durable tension is whether technical disruption can be scaled across privately owned systems without weakening the limits that judicial review is meant to impose.
The trend: U.S. law enforcement is expanding court-authorized cyber operations from suspect-focused access toward disruption and cleanup of active compromises.
Related: DOJ · FBI · FBI disrupts Russian cyberespionage operation · Court documents detail FBI hacking operation · Judge orders disclosure of FBI hacking code
Related Coverage
- Justice Department announces court-authorized effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities U.S. Department of Justice
- FBI launches operation to remove backdoors from hacked Microsoft Exchange servers TechCrunch · Zack Whittaker
- FBI operation removed web shells from hacked Exchange servers across the US The Record · Catalin Cimpanu
- FBI Agents Secretly Deleted Web Shells From Hacked Microsoft Exchange Servers SecurityWeek · Mike Lennon
- Motion to partially unseal search warrant and related documents and [proposed] order United States Courts Southern District of Texas
- View article us-cert.cisa.gov
- The FBI is remotely hacking hundreds of computers to protect them from Hafnium The Verge · Sean Hollister
- View article HackRead
- View article MSPoweruser
- View article ComputerWeekly.com
- View article BGR
- FBI acts to remove backdoors from hacked Microsoft Exchange servers TechRadar · Mayank Sharma
- FBI hacks into hundreds of infected US servers (and disinfects them) Naked Security · Paul Ducklin
- Daily Digest Of Tech Policy News And Updates (April 14, 2021) MediaNama · Aroon Deep
- NSA and FBI move to help Microsoft with its Exchange Server vulnerabilities Enterprise Times · Ian Murphy
- FBI Removes Web Shells from Infected Exchange Servers infosecurity-magazine.com · Phil Muncaster
- The FBI got a court order to delete backdoors from hacked Exchange servers Engadget · R. Lawler
- NSA Discovers New Vulnerabilities Affecting Microsoft Exchange Servers The Hacker News · Ravie Lakshmanan
- FBI silently removed web shells planted on Microsoft Exchange servers in the US Security Affairs · Pierluigi Paganini
- Microsoft Gets Some Help Beyond Search · Stephen E. Arnold
- FBI deletes web shells from hundreds of compromised Microsoft Exchange servers before alerting admins The Register · Kieren McCarthy
- FBI hacks compromised Exchange servers as more companies get targeted SiliconANGLE · Duncan Riley
- FBI nuked web shells from hacked Exchange Servers without telling owners BleepingComputer · Lawrence Abrams
- With court order, FBI removes hundreds of Exchange Server web shells from US organizations CyberScoop · Sean Lyngaas
- The FBI remotely accessed private Exchange servers to remove web shells iTnews · Ry Crozier
- FBI launches operation to remove malware from computers in US The Hill · Tal Axelrod
- April 2021 Update Tuesday packages now available Microsoft Security Response Center
- Cyber criminals are installing cryptojacking malware on unpatched Microsoft Exchange servers ZDNet · Danny Palmer
- Released: April 2021 Exchange Server Security Updates Microsoft Tech Community
- Compromised Exchange server hosting cryptojacker targeting other Exchange servers Sophos News · Andrew Brandt
- Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild Securelist · Boris Larin
- Supplemental Direction v2 Department of Homeland Security
- Another Critical Vulnerability Patched in SAP Commerce SecurityWeek · Ionut Arghire
- NSA unearths more MS Exchange vulnerabilities ComputerWeekly.com · Alex Scroxton
- Update Windows 10 security now to patch these ‘critical’ flaws TechRadar · Mayank Sharma
- Microsoft releases security updates for Exchange Server following report by the NSA Neowin · Usama Jawad
Discussion
-
@kimzetter
Kim Zetter
on x
This action the feds did to remove the malicious shell code from infected Microsoft Exchange Servers is very similar to what they did with the Coreflood botnet a decade ago when they sent command to infected machine to kill botnet. https://www.wired.com/... https://www.justice.go…
-
@bkopernikus
@bkopernikus
on x
FBI receives warrant for “blanket” warrant, with permission to “benevolently hack” Microsoft Exchange mail servers. https://www.vice.com/...
-
@thegrugq
Thaddeus E. Grugq
on x
Exchange servers that were serving webshells are at high risk of being hacked again now. It is unlikely the webshells will have shared default passwords again. Conclusion: FBI YOLO burned their opportunity to remediate the second wave surge of Exchange hacks. Heckuva job https://…
-
@jason_koebler
Jason Koebler
on x
NEW: FBI got permission to log into computers around the country (that it doesn't own) to actively delete suspected Chinese malware from them https://www.vice.com/...
-
@dalperovitch
Dmitri Alperovitch
on x
Great job by the @FBI @TheJusticeDept in removing Chinese webshells from compromised Exchange servers in the US (via court-authorized action). We highlighted the need for webshell removal action in our recent @lawfareblog piece https://www.justice.gov/...
-
@josephfcox
Joseph Cox
on x
New: FBI got approval to access peoples' computers with Microsoft Exchange Server software, remove shells left by hackers. Shows what the FBI will do more proactively, especially now judges can sign hacking warrants for targets outside their district https://www.vice.com/...
-
@jfslowik
@jfslowik
on x
CISA to USG IT: PATCH EXCHANGE NLT THAN FRIDAY! But I thought this wasn't being exploited in the wild? 🤔 https://cyber.dhs.gov/...
-
@viss
@viss
on x
cool. so you can add the fbi to the list of folks breaking into exchange servers now. https://twitter.com/...
-
@josephfcox
Joseph Cox
on x
File paths related to some of the impacted servers that a judge gave the FBI permission to access https://www.vice.com/... https://twitter.com/...
-
@gossithedog
Kevin Beaumont
on x
The US Gov have issued an emergency directive, saying to patch Exchange by Friday or disconnect the device. Note you need to be on a supported Cumulative Update to get the Security Update, and there is no mitigation to apply this time instead. https://us-cert.cisa.gov/... https:/…
-
@jpwarren
Justin Warren
on x
Uh, if I'm reading this right, the US FBI (with court authorisation) just hacked into ‘hundreds’ of private Exchange servers to “copy and remove malicious web shells” https://www.justice.gov/...
-
@kevinmitnick
Kevin Mitnick
on x
The FBI was given Court approval to access exploited Exchange servers to remove the malicious web shell. Maybe the FBI will start offering a malware removal service whether you like it or not!!! Didn't Apple do the same thing with Zoom and get blowback? https://www.vice.com/...
-
@nsacyber
@nsacyber
on x
NSA urges applying critical Microsoft patches released today, as exploitation of these #vulnerabilities could allow persistent access and control of enterprise networks. https://msrc-blog.microsoft.com/ ...
-
@dnvolz
Dustin Volz
on x
DNSA Anne Neuberger comments on today's Microsoft Exchange Server patch release, which was spurred by vulnerabilities identified about the NSA: “'The U.S. Government will lead by example - we are requiring all agencies to immediately patch their Exchange servers” https://twitter.…
-
@c_c_krebs
Chris Krebs
on x
Happy Patch Tuesday! Time to get patching your Exchange Servers! Some critical vulns this month, with discovery credited to @NSACyber. Looks like a good example of coordinated vuln disclosure. I'd expect @CISAgov guidance for Federal agencies soon. https://techcommunity.microsoft…
-
@uscert_gov
Us-Cert
on x
❗ @CISAgov strongly urges organizations apply Microsoft's April Security Update to mitigate against newly disclosed significant vulnerabilities affecting Exchange Servers. See https://us-cert.gov/... for details & new ED 21-02 Supplemental Direction. #Cybersecurity #InfoSec #IT h…
-
@beckypinkard
Becky Pinkard
on x
Patch ASAP time again peeps! “...four more Critical remote code execution vulnerabilities discovered by the NSA were fixed in Microsoft Exchange today. Two of these vulnerabilities are pre-authentication, which means they do not require attackers to log in to the server first.” h…
-
@da5ch0
@da5ch0
on x
hold on to your butts. and patch all your publicly addressable windows machines, ASAP. seriously. don't put it off. go now. wake up the ops guys or sysadmins if need be. patch. patch now https://twitter.com/...
-
@kaspersky
@kaspersky
on x
While analyzing the CVE-2021-1732 exploit used by the BITTER APT group, our researchers discovered another zero-day that is believed to be linked to the same group. Here's what we know 👇 https://securelist.com/...
-
@josephmenn
Joseph Menn
on x
Microsoft is crediting the NSA with warning it about new ways for hackers to take control of on-premise Exchange servers, which are not yet being seen in the wild. NSA and others urge rapid application of the patches released today. https://twitter.com/...
-
@bobbychesney
Bobby Chesney
on x
VEP (Vulnerabilities Equities Process) in action: https://twitter.com/...
-
@craiu
Costin Raiu
on x
Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild by an unknown APT: https://securelist.com/...
-
@ryanaraine
Ryan Naraine
on x
Kaspersky ninja @oct0xor, @craiu and @Mao_Ware has a root-cause analysis on the Desktop Window Manager(dwm.exe) 0day https://securelist.com/...