/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

The DOJ says the FBI performed a court-approved operation to “copy and remove malicious web shells” on hundreds of hacked Exchange servers across the US

The FBI obtained court approval to access vulnerable computers across the United States.  —  Joseph Cox

VICE Joseph Cox

Context & Ripple Effects

Earlier coverage documented the FBI's use of hacking techniques against more than 1,000 computers, followed by litigation over disclosure of the code used in that operation. That history makes the Exchange action a distinct use of court authority: removing an intrusion tool from victims' systems rather than gathering evidence from suspects.

Later FBI actions against Snake malware used in Russian cyberespionage and the legally authorized disabling of parts of Volt Typhoon's compromised-device operation show a continuing operational role for court-approved technical disruption.

First-order effects

  • Owners of the hundreds of affected Exchange servers have malicious web shells removed through the FBI's court-authorized access, reducing the attackers' foothold on those systems.
  • The DOJ and FBI establish a documented remedial use of judicial authorization to enter compromised U.S. computers and alter malicious code.

Second-order effects

  • The operation gives courts, defenders, and civil-liberties litigants another concrete comparison point to the earlier fight over disclosure of FBI hacking code, shifting scrutiny from investigative access toward government-directed cleanup.
  • Future disruption operations can be framed around the same victim-protection rationale used here, alongside the FBI's later malware and compromised-device interventions.

Third-order effects

  • If this pattern holds, court-authorized cyber operations will increasingly span both evidence collection and remediation, making the scope and safeguards of government access a recurring legal boundary.
  • The durable tension is whether technical disruption can be scaled across privately owned systems without weakening the limits that judicial review is meant to impose.

The trend: U.S. law enforcement is expanding court-authorized cyber operations from suspect-focused access toward disruption and cleanup of active compromises.

Discussion

  • @kimzetter Kim Zetter on x
    This action the feds did to remove the malicious shell code from infected Microsoft Exchange Servers is very similar to what they did with the Coreflood botnet a decade ago when they sent command to infected machine to kill botnet. https://www.wired.com/... https://www.justice.go…
  • @bkopernikus @bkopernikus on x
    FBI receives warrant for “blanket” warrant, with permission to “benevolently hack” Microsoft Exchange mail servers. https://www.vice.com/...
  • @thegrugq Thaddeus E. Grugq on x
    Exchange servers that were serving webshells are at high risk of being hacked again now. It is unlikely the webshells will have shared default passwords again. Conclusion: FBI YOLO burned their opportunity to remediate the second wave surge of Exchange hacks. Heckuva job https://…
  • @jason_koebler Jason Koebler on x
    NEW: FBI got permission to log into computers around the country (that it doesn't own) to actively delete suspected Chinese malware from them https://www.vice.com/...
  • @dalperovitch Dmitri Alperovitch on x
    Great job by the @FBI @TheJusticeDept in removing Chinese webshells from compromised Exchange servers in the US (via court-authorized action). We highlighted the need for webshell removal action in our recent @lawfareblog piece https://www.justice.gov/...
  • @josephfcox Joseph Cox on x
    New: FBI got approval to access peoples' computers with Microsoft Exchange Server software, remove shells left by hackers. Shows what the FBI will do more proactively, especially now judges can sign hacking warrants for targets outside their district https://www.vice.com/...
  • @jfslowik @jfslowik on x
    CISA to USG IT: PATCH EXCHANGE NLT THAN FRIDAY! But I thought this wasn't being exploited in the wild? 🤔 https://cyber.dhs.gov/...
  • @viss @viss on x
    cool. so you can add the fbi to the list of folks breaking into exchange servers now. https://twitter.com/...
  • @josephfcox Joseph Cox on x
    File paths related to some of the impacted servers that a judge gave the FBI permission to access https://www.vice.com/... https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    The US Gov have issued an emergency directive, saying to patch Exchange by Friday or disconnect the device. Note you need to be on a supported Cumulative Update to get the Security Update, and there is no mitigation to apply this time instead. https://us-cert.cisa.gov/... https:/…
  • @jpwarren Justin Warren on x
    Uh, if I'm reading this right, the US FBI (with court authorisation) just hacked into ‘hundreds’ of private Exchange servers to “copy and remove malicious web shells” https://www.justice.gov/...
  • @kevinmitnick Kevin Mitnick on x
    The FBI was given Court approval to access exploited Exchange servers to remove the malicious web shell. Maybe the FBI will start offering a malware removal service whether you like it or not!!! Didn't Apple do the same thing with Zoom and get blowback? https://www.vice.com/...
  • @nsacyber @nsacyber on x
    NSA urges applying critical Microsoft patches released today, as exploitation of these #vulnerabilities could allow persistent access and control of enterprise networks. https://msrc-blog.microsoft.com/ ...
  • @dnvolz Dustin Volz on x
    DNSA Anne Neuberger comments on today's Microsoft Exchange Server patch release, which was spurred by vulnerabilities identified about the NSA: “'The U.S. Government will lead by example - we are requiring all agencies to immediately patch their Exchange servers” https://twitter.…
  • @c_c_krebs Chris Krebs on x
    Happy Patch Tuesday! Time to get patching your Exchange Servers! Some critical vulns this month, with discovery credited to @NSACyber. Looks like a good example of coordinated vuln disclosure. I'd expect @CISAgov guidance for Federal agencies soon. https://techcommunity.microsoft…
  • @uscert_gov Us-Cert on x
    ❗ @CISAgov strongly urges organizations apply Microsoft's April Security Update to mitigate against newly disclosed significant vulnerabilities affecting Exchange Servers. See https://us-cert.gov/... for details & new ED 21-02 Supplemental Direction. #Cybersecurity #InfoSec #IT h…
  • @beckypinkard Becky Pinkard on x
    Patch ASAP time again peeps! “...four more Critical remote code execution vulnerabilities discovered by the NSA were fixed in Microsoft Exchange today. Two of these vulnerabilities are pre-authentication, which means they do not require attackers to log in to the server first.” h…
  • @da5ch0 @da5ch0 on x
    hold on to your butts. and patch all your publicly addressable windows machines, ASAP. seriously. don't put it off. go now. wake up the ops guys or sysadmins if need be. patch. patch now https://twitter.com/...
  • @kaspersky @kaspersky on x
    While analyzing the CVE-2021-1732 exploit used by the BITTER APT group, our researchers discovered another zero-day that is believed to be linked to the same group. Here's what we know 👇 https://securelist.com/...
  • @josephmenn Joseph Menn on x
    Microsoft is crediting the NSA with warning it about new ways for hackers to take control of on-premise Exchange servers, which are not yet being seen in the wild. NSA and others urge rapid application of the patches released today. https://twitter.com/...
  • @bobbychesney Bobby Chesney on x
    VEP (Vulnerabilities Equities Process) in action: https://twitter.com/...
  • @craiu Costin Raiu on x
    Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild by an unknown APT: https://securelist.com/...
  • @ryanaraine Ryan Naraine on x
    Kaspersky ninja @oct0xor, @craiu and @Mao_Ware has a root-cause analysis on the Desktop Window Manager(dwm.exe) 0day https://securelist.com/...