Frequently Asked Questions

Threats & Vulnerabilities

What Exchange vulnerabilities were exploited in the Squirrelwaffle campaign?

The Squirrelwaffle campaign exploited three Microsoft Exchange vulnerabilities: CVE-2021-26855 (ProxyLogon), CVE-2021-34473, and CVE-2021-34523 (both ProxyShell). Attackers used these vulnerabilities to access user SIDs, emails, and execute PowerShell commands as NT AUTHORITY\SYSTEM, enabling them to hijack internal email chains for malicious spam delivery. Note: These vulnerabilities require prompt patching to prevent exploitation. Source

How did attackers use ProxyShell to gain access to Exchange servers?

Attackers leveraged ProxyShell by exploiting the URL normalization process of the explicit Logon URL. If the suffix was autodiscover/autodiscover.json, the logon email was removed, granting arbitrary backend URLs the same access as the Exchange machine account (NT AUTHORITY\SYSTEM). They then used the X-Rps-CAT query string parameter to impersonate a local administrator and execute PowerShell commands. Note: This technique bypasses mailbox restrictions and enables privilege escalation. Source

What was the impact of the Squirrelwaffle attack on internal email communications?

The attackers hijacked legitimate internal email chains to deliver malicious spam as replies, using real account names from the victim's domain. This internal routing bypassed external mail gateways and filtering, increasing the likelihood that recipients would trust and interact with the malicious links. Note: Internal-only delivery can evade traditional security controls. Source

What payloads were delivered in the Squirrelwaffle campaign?

The spam emails contained links to external URLs that dropped ZIP files. These ZIP files included malicious Microsoft Excel sheets with Excel 4.0 macros. When opened, the macros downloaded and executed a DLL associated with Qbot malware. Note: Macros in Office documents remain a common initial infection vector. Source

How did the attackers evade detection during the Squirrelwaffle campaign?

The attackers avoided lateral movement and did not execute malware directly on the Exchange servers. By routing spam internally and minimizing suspicious network activity, they reduced the chances of triggering alerts before launching the malicious email campaign. Note: This approach can bypass many endpoint and network-based detection tools. Source

Cymulate Platform Features & Capabilities

How can Cymulate help organizations defend against Exchange vulnerabilities like ProxyShell and ProxyLogon?

Cymulate enables organizations to continuously validate their defenses against real-world threats, including Exchange vulnerabilities such as ProxyShell and ProxyLogon. The platform automates exposure validation, simulates attack scenarios, and provides actionable remediation guidance to close the risk-to-fix gap. Note: Cymulate does not replace patching and should be used alongside regular vulnerability management. Learn more

What types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform is designed to simulate diverse attack scenarios for comprehensive security validation. Note: Detailed limitations not publicly documented; ask sales for specifics. Source

What is Cymulate's Immediate Threats Module and how does it benefit users?

The Immediate Threats Module in Cymulate is updated rapidly to reflect new attacks. Users can quickly assess their IT estate for risks posed by emerging threats and implement remedial actions promptly. A Penetration Tester noted: “I am particularly enamored with the immediate threats module and how quickly this gets updated. In short if an attack is new, you can quickly assess your IT estate for how much of a risk is posed to you and implement remedial action quickly.” Note: The module's effectiveness depends on timely updates and user action. Source

What integrations does Cymulate support?

Cymulate integrates with over 50 security tools, including SIEM platforms (Azure Sentinel, Splunk, CrowdStrike Falcon LogScale), EDR and anti-malware solutions (CrowdStrike Falcon, Carbon Black EDR, Cisco Secure Endpoint), cloud security (AWS GuardDuty, Check Point CloudGuard), web gateways (Cisco Umbrella), vulnerability management (Rapid7 InsightVM), and others like Microsoft Defender, Palo Alto Networks, Wiz, and Zscaler. Note: Integration availability may vary by package; confirm with Cymulate for your environment. Source

Use Cases & Business Impact

Who can benefit from using Cymulate?

Cymulate is designed for CISOs, VP Security, SecOps Directors, SOC Leaders, Detection Engineers, Blue Team Leads, Red Teams, Vulnerability Management, GRC/Compliance, and IT/Cloud teams. It is suitable for organizations of all sizes and industries seeking to proactively manage and validate their cybersecurity posture, prioritize high-risk issues, and communicate cybersecurity value to stakeholders. Note: Best fit for organizations with dedicated security teams; smaller organizations may require additional support. Source

What business impact can customers expect from using Cymulate?

Organizations using Cymulate report an average 30% increase in threat prevention, 90% improvement in threat detection, 52% reduction in critical exposures, 60% boost in operational efficiency, and threat validation 40X faster than manual methods. For example, Hertz Israel achieved an 81% reduction in cyber risk within four months. Note: Results may vary based on implementation scope and organizational maturity. Source

What are some real-world case studies demonstrating Cymulate's value?

Case studies include: Hertz Israel reduced cyber risk by 81% in four months (risk-to-fix gap); LV= proved security readiness with near real-time data; a retail organization became 12x faster at assessing controls; Banco PAN prioritized vulnerabilities and optimized controls; UK Bank improved collaboration across teams; Saffron Building Society proved compliance with actionable remediation; Nemours improved detection and response; Insurance Leader validated exposure scoring for leadership. Note: Outcomes depend on organizational context and engagement. See case studies

Security & Compliance

What security and compliance certifications does Cymulate hold?

Cymulate is SOC2 Type II certified and holds ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1 certifications. These cover information security, privacy, cloud security, and compliance with the Cloud Controls Matrix. Note: Certification scope and coverage may change; verify with Cymulate for the latest status. Source

What product security features does Cymulate offer?

Cymulate offers 2-Factor Authentication (2FA), Single Sign-On (SSO), role-based access controls (RBAC), and data encryption in transit and at rest. The platform also supports GDPR compliance with secure development life cycle procedures, code review, vulnerability scanning, and oversight by a Data Protection Officer (DPO) and Chief Information Security Officer (CISO). Note: Feature availability may depend on subscription tier. Source

Implementation & Ease of Use

How long does it take to implement Cymulate and how easy is it to start?

Cymulate is designed for rapid deployment, operating in agentless mode without the need for additional hardware or complex configurations. Users can start running simulations almost immediately, with an intuitive dashboard and minimal resources required. Customers have access to email and chat support, webinars, e-books, and technical articles. Raphael Ferreira, Cybersecurity Manager, stated: “Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights into how you can improve your security posture.” Note: Implementation time may vary based on environment complexity. Source

What feedback have customers given about Cymulate's ease of use?

Customers consistently praise Cymulate for its intuitive design and ease of use. Testimonials include: “Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights” (Raphael Ferreira, Cybersecurity Manager); “User-friendly and easy to deploy, it’s the best solution for communicating risks to management” (IT Security & Risk Management Assistant); “The platform is very easy to understand for making the team understand about the potential threats” (Security Consultant). Note: Some advanced features may require additional training. Source

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model, customized to fit the unique needs of each organization. Pricing depends on the package selected, number of assets covered, and scenarios/features chosen. For a tailored quote, organizations should schedule a demo with Cymulate's team. Note: Exact pricing is not publicly listed; contact Cymulate for details. Source

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate offers AI-driven remediation guidance, a daily-updated attack scenario library, and an AI Copilot for automated test creation. It provides continuous, automated testing and is recognized as a Momentum Leader by G2 and a Customer’s Choice in the 2025 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation. AttackIQ may offer different integrations or workflows. Choose Cymulate for rapid, actionable validation; choose AttackIQ if you require specific integrations not covered by Cymulate. Note: Cymulate's AI Copilot and daily updates are not available in all competitor platforms. Source

How does Cymulate compare to Mandiant Security Validation?

Cymulate emphasizes AI and automation, rapid deployment, easy integrations, and an intuitive dashboard. It features a comprehensive attack library with daily updates and actionable remediation. Mandiant Security Validation may offer deeper threat intelligence or incident response services. Choose Cymulate for ease of use and automation; choose Mandiant if you need integrated incident response. Note: Cymulate does not provide incident response services. Source

How does Cymulate compare to Pentera?

Cymulate combines breach simulation, automated red teaming, and deep security control integrations. It allows custom attack chains from a library of over 100,000 actions and features an AI attack planner. Pentera may focus more on automated penetration testing. Choose Cymulate for continuous exposure validation and custom offensive testing; choose Pentera for automated pen testing. Note: Cymulate does not replace full-scope manual penetration testing. Source

How does Cymulate compare to Picus Security?

Cymulate delivers full kill-chain coverage, including cloud control validation, and features no-code workflows with a large attack action library. It is recognized as a Momentum Leader in Breach and Attack Simulation by G2 and as a Customer’s Choice in the 2025 Gartner Peer Insights Voice of the Customer. Picus Security may offer different reporting or integration options. Choose Cymulate for cloud validation and automation; choose Picus if you need specific integrations. Note: Cymulate's cloud validation features may not be present in all competitor platforms. Source

How does Cymulate compare to SafeBreach?

Cymulate leverages AI and automation for exposure validation, offers the industry’s largest attack library with daily updates, and features intuitive dashboards and centralized validation. Customers report 40X faster threat validation and 85% improvement in detection accuracy. SafeBreach may offer different reporting or workflow options. Choose Cymulate for speed and automation; choose SafeBreach if you need specific integrations. Note: Cymulate's centralized validation may not cover all environments. Source

Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Squirrelwaffle Exploits ProxyShell and ProxyLogon to Hijack Email Chains

November 23, 2021

Researchers identified evidence of exploits targeting the vulnerabilities CVE-2021-26855, CVE-2021-34473, and CVE-2021-34523 within IIS logs on three compromised Exchange servers during separate intrusions. These CVEs were previously associated with the ProxyLogon (CVE-2021-26855) and ProxyShell (CVE-2021-34473 and CVE-2021-34523) attack chains.

Analysis of the IIS logs revealed that the threat actor used a publicly available exploit, allowing them to access user SIDs and emails. They could also search for and download targeted emails.

Exploitation via ProxyShell

The ProxyShell vulnerability leverages the URL normalization process of the explicit Logon URL. If the suffix is autodiscover/autodiscover.json, the logon email is removed from the URL, granting arbitrary backend URLs the same access as the Exchange machine account (NT AUTHORITY\SYSTEM).

Though NT AUTHORITY\SYSTEM lacks a mailbox, Exchange’s PowerShell remoting feature can be accessed directly through this vulnerability. By using the X-Rps-CAT query string parameter, attackers can deserialize and restore a user’s identity, enabling them to impersonate a local administrator and execute PowerShell commands.

Malicious Email Campaign Observations

Spam Email Delivery

In one observed intrusion, attackers hijacked legitimate email chains to send malicious spam as replies. All internal users on the affected network received emails written in English, though different regions saw other languages used. True account names from the victim’s domain were used as sender and recipient, increasing the likelihood that recipients would trust the messages and click on the malicious links.

Email Path Analysis

Analysis of email headers revealed that the spam emails were transmitted internally between the three Exchange servers. This internal routing bypassed external message transfer agents (MTAs), open mail relays, and mail gateways, reducing the chances of detection or quarantine.

Techniques to Evade Detection

The attacker avoided using tools for lateral movement or executing malware on the Exchange servers. This minimized suspicious network activity and avoided triggering alerts prior to the malicious email campaign’s launch.

The spam emails contained links leading to the following URLs:

  • aayomsolutions[.]co[.]in/etiste/quasnam[]-4966787
  • aparnashealthfoundation[.]aayom.com/quasisuscipit/totamet[-]4966787

Clicking these links dropped a ZIP file onto the victim’s machine.

Malicious Payloads

The ZIP file contained a malicious Microsoft Excel sheet embedded with Excel 4.0 macros designed to download and execute a malicious DLL associated with Qbot malware.

Delivery Method

The macros executed the DLL download and execution upon opening the Excel file, enabling the malware to infect the victim’s system without requiring any lateral movement or additional malware execution on the Exchange servers.

Threat Actor Objectives and Impact

Exploitation for Spam Campaigns

The attackers exploited Exchange servers to deliver internal emails, ensuring the spam campaign remained within the organization’s network. By avoiding external mail paths, the attack bypassed traditional filtering mechanisms, making it more likely for users to interact with the malicious files.

User Manipulation

The carefully crafted spam campaign aimed to catch users off-guard, exploiting trust in internal emails. This increased the likelihood of victims clicking the links and opening the malicious Excel or Word files, initiating the infection process.

Conclusion

This attack underscores the sophistication of exploiting Exchange vulnerabilities for malicious campaigns. By leveraging ProxyShell vulnerabilities and internal email delivery, the attackers minimized detection opportunities and maximized impact.

Organizations should prioritize patching known vulnerabilities like CVE-2021-26855, CVE-2021-34473, and CVE-2021-34523. Additionally, implementing advanced monitoring and security solutions is essential to detect abnormal activities, even within internal email communications.