Hackers are Targeting Microsoft Exchange servers using exploits to distribute malware. The vulnerabilities allow hackers to bypass detection by sending emails with malware attachments or messages containing malicious links to internal employees. This is done by abusing the Exchange server’s built-in features, ProxyShell and ProxyLogon.
Threat actors use a number of strategies to mislead the user into opening the email and clicking on the malicious attachment. They can impersonate a legitimate sender, include a sense of urgency or click-bait subject line, or use a low-quality crafted email that looks like it was sent from an unprofessional company.
TrendMicro researchers have discovered a clever tactic of using compromised Microsoft Exchange servers to distribute malicious emails to a company’s internal users.
All this is done by sending an infected email to the victim and then forwarding it to all of the victim’s contacts in their address book.
The emails will appear to be sent from the victim’s own account and the subject line will be formatted like a normal email.
It is believed that the hackers behind this attack are from the ‘TR’ group, it’s a well-known hacker group that distributes emails with malicious attachments that drop malware. Even TR has been spotted in the past using the following file formats in their emails:-
The payloads that are used are:-
Moreover, Trend Micro has claimed that “In the same intrusion, we analyzed the email headers for the received malicious emails, the mail path was internal (between the three internal exchange servers’ mailboxes), indicating that the emails did not originate from an external sender, open mail relay, or any message transfer agent (MTA).”
Since these emails are coming from the same internal network, it is safe to assume that they are legitimate. The tone of the emails is conversational while still maintaining a professional tone.
It’s an excellent tactic used by hackers for not raising any alarms on the email protection systems.
Here are the vulnerabilities that are exploited:-
For later backdoor access the hackers deploy ransomware or install webshells by exploiting both ProxyShell and ProxyLogon vulnerabilities. And these attacks god so bad that without informing the servers’ owners the FBI removed webshells from all the available compromised US-based Microsoft Exchange servers.
That’s why the cybersecurity experts strongly recommend users immediately update their Exchange servers, and make sure the firewall is up to date and well configured.
Even you should also make sure that you’re running the latest version of the anti-malware software for your operating system. If you’re not sure, then contact your IT support provider.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.
Brinker, an innovative narrative intelligence platform dedicated to combating disinformation and influence campaigns, has been…
A recent investigation by cybersecurity researchers has uncovered a large-scale malware campaign leveraging the DeepSeek…
A recent malware campaign has been observed targeting the First Ukrainian International Bank (PUMB), utilizing…
A newly discovered malware, dubbed Trojan.Arcanum, is targeting enthusiasts of tarot, astrology, and other esoteric…
A sophisticated phishing campaign orchestrated by a Russian-speaking threat actor has been uncovered, revealing the…
A sophisticated malware campaign has compromised over 1,500 PostgreSQL servers, leveraging fileless techniques to deploy…