Wednesday, March 26, 2025
HomeMalwareHackers Attack MS Exchange Servers Using ProxyShell & ProxyLogon Exploits to Distribute...

Hackers Attack MS Exchange Servers Using ProxyShell & ProxyLogon Exploits to Distribute Malware

Published on

SIEM as a Service

Follow Us on Google News

Hackers are Targeting Microsoft Exchange servers using exploits to distribute malware. The vulnerabilities allow hackers to bypass detection by sending emails with malware attachments or messages containing malicious links to internal employees. This is done by abusing the Exchange server’s built-in features, ProxyShell and ProxyLogon.

Threat actors use a number of strategies to mislead the user into opening the email and clicking on the malicious attachment. They can impersonate a legitimate sender, include a sense of urgency or click-bait subject line, or use a low-quality crafted email that looks like it was sent from an unprofessional company.

TrendMicro researchers have discovered a clever tactic of using compromised Microsoft Exchange servers to distribute malicious emails to a company’s internal users. 

All this is done by sending an infected email to the victim and then forwarding it to all of the victim’s contacts in their address book.

The emails will appear to be sent from the victim’s own account and the subject line will be formatted like a normal email.

Microsoft Exchange infection

It is believed that the hackers behind this attack are from the ‘TR’ group, it’s a well-known hacker group that distributes emails with malicious attachments that drop malware. Even TR has been spotted in the past using the following file formats in their emails:-

  • Microsoft Office Files (.doc, .xls, .ppt)
  • Rich Text Format (.rtf) 
  • Portable Document Format (.pdf)
  • Single File Web Page (.mht)
  • Compiled HTML (.chm)
  • Compiled Help File (.chm or .hlp)
  • Shell Executable files (.exe, .com, or .bat)

The payloads that are used are:-

  • Qbot
  • IcedID
  • Cobalt Strike
  • SquirrelWaffle

Moreover, Trend Micro has claimed that “In the same intrusion, we analyzed the email headers for the received malicious emails, the mail path was internal (between the three internal exchange servers’ mailboxes), indicating that the emails did not originate from an external sender, open mail relay, or any message transfer agent (MTA).”

Since these emails are coming from the same internal network, it is safe to assume that they are legitimate. The tone of the emails is conversational while still maintaining a professional tone.

It’s an excellent tactic used by hackers for not raising any alarms on the email protection systems.

Vulnerabilities Exploited

Here are the vulnerabilities that are exploited:-

  • CVE-2021-34473: The pre-auth path confusion
  • CVE-2021-34523: Exchange PowerShell backend elevation-of-privilege
  • CVE-2021-26855: The pre-authentication proxy vulnerability

Always keep your Exchange servers updated

For later backdoor access the hackers deploy ransomware or install webshells by exploiting both ProxyShell and ProxyLogon vulnerabilities. And these attacks god so bad that without informing the servers’ owners the FBI removed webshells from all the available compromised US-based Microsoft Exchange servers.

That’s why the cybersecurity experts strongly recommend users immediately update their Exchange servers, and make sure the firewall is up to date and well configured. 

Even you should also make sure that you’re running the latest version of the anti-malware software for your operating system. If you’re not sure, then contact your IT support provider.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

APT Hackers Exploit Google Chrome Zero-Day in Operation ForumTroll to Bypass Sandbox Protections

In mid-March 2025, Kaspersky researchers uncovered a sophisticated APT attack, dubbed Operation ForumTroll, which...

New Sophisticated Linux Backdoor Targets OT Systems via 0-Day RCE Exploit

Researchers at QiAnXin XLab have uncovered a sophisticated Linux-based backdoor dubbed OrpaCrab, specifically targeting...

New Chrome Installer Fails on Windows 10 & 11 With “This app can’t run on your PC” Error

A recent snag in Google's Chrome distribution process has left Windows users unable to...

North Korean Kimsuky Hackers Deploy New Tactics and Malicious Scripts in Recent Attacks

Security researchers have uncovered a new attack campaign by the North Korean state-sponsored APT...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Raspberry Robin Unveils 200 Unique Domains Used by Threat Actors

In a significant development, cybersecurity firm Silent Push has identified nearly 200 unique command...

Cybercriminals Bypass Security Using Legitimate Tools & Browser Extensions to Deliver Malware

In the second half of 2024, cybercriminals have increasingly leveraged legitimate Microsoft tools and...

Banking Malware Infects 248,000 Mobile Users Through Social Engineering Techniques

In 2024, the number of users affected by mobile banking malware skyrocketed to nearly...