An unpatched vulnerability in Microsoft Exchange Server appears to have been the entry point for the attackers who breached the systems of the UK Elec.
Kaspersky has detailed the activity of ToddyCat, a relatively new ATP that has been targeting high-profile entities in Europe and Asia for more than a year and a half.