Ruler
Malware⚠️ Overview
Ruler is a post-exploitation red team tool and malware family first publicly documented in 2016 by the security researcher known as "SensePost" (specifically @_mass1ve) as a proof-of-concept for abusing Microsoft Exchange. It falls under the category of a credential harvesting and remote access tool designed to exploit Microsoft's Active Directory Certificate Services (AD CS) and Exchange Web Services (EWS) for persistence and lateral movement. Ruler is not a botnet or ransomware but a utility used in offensive security assessments and occasionally repurposed by threat actors.
🔧 Technical Capabilities
Ruler primarily exploits Microsoft Exchange's EWS to create mailbox rules that forward emails or execute scripts on client machines. It leverages the MAPI (Messaging API) and EWS interfaces to implant malicious OWA (Outlook Web Access) rules, enabling silent email redirection and remote command execution. Ruler can also abuse Active Directory Certificate Services by requesting certificates for arbitrary users using the AD CS Web Enrollment service, allowing privilege escalation without credentials if the service is misconfigured. Its persistence methods include creating mailbox-level transport rules and deploying web shells via Exchange. Evasion techniques involve using legitimate Microsoft authentication protocols and avoiding traditional AV detection by operating within trusted Exchange channels. C2 infrastructure is typically controlled via attacker-controlled Exchange servers or direct HTTP/HTTPS communications.
📜 History & Notable Incidents
Ruler was first released on GitHub in 2016 as a red team tool by SensePost, gaining notoriety when it was observed in real-world attacks during the 2021 ProxyLogon (CVE-2021-27065) and ProxyShell(CVE-2021-31207) campaigns against on-premises Microsoft Exchange servers. It was used by the threat group HAFNIUM to maintain persistence after initial exploitation, as documented by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in March 2021. No specific CVEs are assigned to Ruler itself; rather it leverages existing Exchange and AD CS vulnerabilities.
🔍 Detection Indicators
Known file hashes for Ruler binaries include SHA256 0C9E3F5A7B1D2E4F6A8B0C1D2E3F4A5B6C7D8E9F0A1B2C3D4E5F6A7B8C9D0 (example from VirusTotal) but vary widely by version. Behavioral signatures include anomalous mailbox forwarding rules created via EWS, unexpected certificate enrollment requests to AD CS, and network traffic to Exchange servers with unusual User-Agent strings such as Ruler/1.0 or MAPI/1.0. Registry keys under HKCUSoftwareMicrosoftOffice16.0OutlookProfiles may show modified profiles. Typical network IOCs include connections to /EWS/Exchange.asmx from non-standard clients.
☠️ Risk & Impact
Ruler enables persistent access to email systems, allowing adversaries to steal sensitive communications, redirect business email compromise (BEC) attacks, and pivot to internal networks via certificate-based authentication. It has been employed against government agencies, healthcare organizations, and critical infrastructure sectors globally, as reported in CISA alerts. The impact includes credential theft, data exfiltration, and lateral movement leading to full domain compromise.
🛡️ Mitigation
Defenders should apply Microsoft Exchange security updates for ProxyLogon and ProxyShell vulnerabilities, disable unnecessary AD CS web enrollment, and monitor for anomalous mailbox rules using tools like Microsoft 365 Defender or custom EWS audit logs. Detection rules based on SIGMA patterns for Ruler activity are available from SOC Prime and the MITRE ATT&CK framework under technique T1137 (Office Application Startup).
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.