Friday, April 25, 2025
HomeCVE/vulnerabilityHackers Exploit Microsoft Exchange Vulnerabilities To Drop Babuk Ransomware

Hackers Exploit Microsoft Exchange Vulnerabilities To Drop Babuk Ransomware

Published on

SIEM as a Service

Follow Us on Google News

The Cisco security researchers informed recently that another threat actors organization is targeting the Microsoft Exchange Server vulnerabilities to disseminate the ransomware “Babuk”, and to do so, they have not reinforced the ProxyShell vulnerability.

The ProxyShell is a general term for 3 Exchange Server vulnerabilities that have:- 

However, all these 3 exchange servers belong to the following vulnerabilities that were already patched by Microsoft in April and in May this year:-

- Advertisement - Google News
  • Remote program attack vulnerability
  • Permission expansion vulnerabilities
  • Security function bypass vulnerabilities

Initiates with Microsoft Exchange 

The Babuk ransomware attack initiates with a DLL or with a .NET executable that is grounded on the Exchange server by utilizing the ProxyShell vulnerability.

This vulnerability eventually connects to ‘pastebin.pl’, and later, it downloads a payload that is oppressed into memory, and the hackers then inject it into a NET Framework process that ultimately encrypts the device with the Babuk Ransomware.

Pathways to drop the DLL and .NET modules followed by Tortilla campaign in which the Babuk ransomware was distributed:-

  • Microsoft Exchange autodiscover server-side request forgery attempt
  • Atlassian Confluence OGNL injection remote code execution attempt
  • Apache Struts remote code execution attempt
  • WordPress wp-config.php access via directory traversal attempt
  • SolarWinds Orion authentication bypass attempt
  • Oracle WebLogic Server remote command execution attempt
  • Liferay arbitrary Java object deserialization attempt

So, to prevent the servers from being exploited in attacks, admins are strongly recommended to upgrade their servers to the latest versions.

Exploiting Babuk 

Initially, Babuk Locker is a ransomware operation that targets businesses, and later the threat actors encrypt their data in double-extortion attacks.

The threat actors have started utilizing the ransomware with the motive of launching their planned attacks, and all this was noted when the first version of Babuk ransomware and a builder got leaked on hacking forums.

The security experts pronounced that the ransom note that has been used in these attacks has asked for a low $10,000 in Monero, but it’s been declared that the original Babuk operation was not conducted as the original was demanded larger ransomware in Bitcoin.

Hackers Targeted the USA

In this event which is referred as Tortilla, the hackers targeted some attacks in the countries like Germany, Thailand, Brazil, and the U.K., and most of Tortilla’s targets are U.S.-based. 

While the IP addresses that were found in these attacks were located in Moscow, Russia, and that’s why it clearly intimates the origin of these attacks.

Moreover, the security analysts also noticed the corporate IT staff build multi-level security, and not only this, but they also use behavioral analysis products so that they can easily detect threats and protect the endpoints and Exchange Server.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

DragonForce and Anubis Ransomware Gangs Launch New Affiliate Programs

Secureworks Counter Threat Unit (CTU) researchers have uncovered innovative strategies deployed by the DragonForce...

“Power Parasites” Phishing Campaign Targets Energy Firms and Major Brands

Silent Push Threat Analysts have uncovered a widespread phishing and scam operation dubbed "Power...

Threat Actors Register Over 26,000 Domains Imitating Brands to Deceive Users

Researchers from Unit 42 have uncovered a massive wave of SMS phishing, or "smishing,"...

Russian Hackers Attempt to Sabotage Digital Control Systems of Dutch Public Service

The Dutch Defense Ministry has revealed that critical infrastructure, democratic processes, and North Sea...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

WooCommerce Users Targeted by Fake Security Vulnerability Alerts

A concerning large-scale phishing campaign targeting WooCommerce users has been uncovered by the Patchstack...

Chrome UAF Process Vulnerabilities Actively Exploited

Security researchers have revealed that two critical use-after-free (UAF) vulnerabilities in Google Chrome’s Browser...

Spring Security Vulnerability Exposes Valid Usernames to Attackers

A newly identified security vulnerability, CVE-2025-22234, has exposed a critical weakness in the widely-used...