HomeSecurityMicrosoft Exchange servers: Government hacking groups exploit bug!

Microsoft Exchange servers: Government hacking groups exploit bug!

Multiple groups backed by the government are exploiting a vulnerability in the Microsoft Exchange email servers for which a patch was recently released.

The exploit attempts were first spotted by UK -based cybersecurity firm Volexity on Friday and were confirmed to ZDNet today by a source.

Volexity did not share the names of the hacking groups exploiting this Exchange vulnerability. The source described the hacking groups as “all the big players,” but also declined to name groups or countries.

Microsoft Exchange servers: Government hacking groups exploit bug!

The Microsoft Exchange vulnerability

These state-sponsored support groups are exploiting a vulnerability in Microsoft Exchange email servers, which Microsoft disclosed last month.

The vulnerability is tracked with the identifier CVE-2020-0688. Below is a summary of the technical details of the vulnerability:

  • During installation, Microsoft Exchange servers fail to generate a unique cryptographic key for the Exchange control panel.
  • This means that all Microsoft Exchange email servers released in the last 10 years use identical cryptographic keys (validationKey and decryptionKey) for their control panel backend.
  • Attackers can send malformed requests to the Exchange control panel that contain malicious serialized data.
  • Since the hackers know the control panel's encryption keys, they can ensure that the serialized data is not unprocessed, resulting in malicious code in the Exchange server's backend.
  • The malicious code runs with SYSTEM privileges, giving the attackers full control of the server.

Microsoft released patches for this bug on February 11, when it also warned system administrators to install the patches as soon as possible, anticipating future attacks.

Nothing happened for almost two weeks. Things scaled towards the end of the month, however, when the Zero-Day Initiative, which reported the bug to Microsoft, published a technical report that describes the bug in detail and how it worked.

The report served as a roadmap for security researchers, who used the information contained therein to build test methodsso they could test their own servers and create detection rules and prepare mitigations.

Τουλάχιστον τρια από αυτά τα proof-of-concepts βρέθηκαν στο GitHub [1, 2, 3]. Ακολούθησε σύντομα μια μονάδα Metasploit.

Just as in many other cases, when the technical details and the code were released publicly, the hackers also began to pay attention.

On February 26, a day after the launch of the Zero-Day Initiative report, hacker groups began scanning the internet for Exchange servers, compiling lists of vulnerable servers they could target later. The first scans of this type were identified by Intel Bad Packets.

Now, according to Volexity, scans for Exchange servers have turned into real attacks.

The first to use this flaw were the APTs, a term often used to describe hacker groups that are funded by the state.

However, other groups are also expected to follow suit. Security researchers said they expect the bug to become very popular with ransomware that regularly target enterprise.
However, this Exchange vulnerability is not easy to exploit. Security experts do not see this bug being compromised by script kiddies (a term used to describe low-level, unskilled hackers).

To exploit the Exchange CVE-2020-0688 vulnerability, hackers need the credentials of an email on Exchange – something that script kiddies usually do not have.

The CVE-2020-0688 security flaw is a so-called post- authentication. Hackers must first log in and then execute the malicious payload that hijacks the victim's email server.

But while this restriction will keep child scripts away, it won't keep APTs and ransomware gangs out, experts said.

APTs and ransomware gangs often spend most of their time launching phishing campaigns,through which they obtain the email credentials of a company's employees.

If an organization enforces two-factor authentication (2FA) for email accounts, these credentials are essentially useless, as hackers cannot bypass 2FA.

The CVE-2020-0688 bug allows APTs to finally find a purpose for older accounts protected by 2FA that have been retired months or years ago.

They can use any of these older credentials without having to bypass 2FA, but even manage to take over the victim.

Organizations that have “APTs” or “ransomware” in their threat matrix are advised to update their Exchange email servers with the February 2020 security updates as soon as possible.

Hacking email servers is the most important point of APT attacks, as this allows them to monitor and read a company's email communications

This post from TrustedSec contains instructions on how to detect an Exchange server that has already been hacked via this bug.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS