HomeSecurityLightNeuron malware infects Microsoft Exchange Server

LightNeuron malware infects Microsoft Exchange Server

exchange

A malware that uses the core functions of Microsoftto remotely monitor and control computer systems was recently discovered by ESET.

Researchers said this week that the highly dangerous software, known as LightNeuron, is particularly difficult for administrators to detect because it exploits legitimate Exchange credentials.

Specifically, LightNeuron combines an infected DLL and a specially designed Transport Agent. Designed for things like spam filtering and secure attachments, Transport Agents analyze all messages entering and leaving a server.

Having control of a Transport Agent on a server is a very good practice for a hacker who wants to secretly monitor a company or organization.

“In the few cases we studied, LightNeuron runs with SYSTEM privileges. It is typically difficult to gain this level of privilege on a Microsoft Exchange Server, as it is one of the most critical assets in an organization. It is likely that it will remain undetected for months or even years,” ESET states.

The other step of the infection is a malicious DLL, which processes and executes additional commands, such as sending mail, recording and transmitting activity, and modifying messages traveling through the server.

In the case of LightNeuron, ESET discovered, the malware inserted commands into the hex code of a PDF or JPG file. The attacker would put the command in the file and send it as an attachment to a message to the infected server. The message would be detected by LightNeuron's Transport Agent, which would then pass it to the DLL, where it would access the image information and execute commands within it.

This way, hackers have the ability to monitor and control a system without ever being detected by security filters. However, even if they manage to detect the malware, eliminating it is quite difficult, since it requires a complete rewrite of the server.

Security researchers recommend that administrators secure their servers against LightNeuron. Administrator accounts should be well secured with 2FA, access to PowerShell commands should be strictly restricted, and Transport Agent installations should be closely monitored.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS