The ProxyShell vulnerabilities allow attackers to elevate privileges on the Exchange PowerShell backend and perform unauthenticated, remote code execution.
Written in C++, the Sardonic backdoor allows its operators to collect system information, execute arbitrary commands, and load and execute additional plugins.