WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Threat Awareness – New IceApple Toolset Being Deployed on Microsoft Exchange Servers
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – New IceApple Toolset Being Deployed on Microsoft Exchange Servers

Author: Alec Davison

Created: Thursday, May 12, 2022 - 18:27

Categories: Cybersecurity

Security researchers have discovered a new sophisticated post-exploitation framework being primarily deployed on Exchange servers, dubbed IceApple. The toolset was discovered by CrowdStrike after an alert triggered on a new customer’s Microsoft OWA deployment. Researchers believe the developers behind IceApple prioritize keeping a low profile in network environments to achieve long-term objectives in targeted attacks. Since first being observed in late 2021, threat actors behind IceApple have targeted entities in the technology, academic, and government sectors across the globe. IceApple has been deployed on Microsoft Exchange Servers and can also operate in Internet Information Services (IIS) web applications. The framework “comes with at least 18 modules that help the attacker discover relevant machines on the network, steal credentials, delete files and directories, or exfiltrate valuable data,” according to BleepingComputer. Additionally, to avoid detection, IceApple appears to use multiple evasion techniques. Finally, researchers believe that based on the observed behavior of IceApple, its likely operated by a state-sponsored threat actor. Read more at BleepingComputer.

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar