Microsoft has issued a warning after discovering multiple threats lurking in already compromised Exchange Servers. Although many have received security updates, they are still vulnerable to attacks .

Microsoft is warning about potential surveillance attacks targeting already compromised Exchange Servers, especially if the attackers used web shell scripts to gain persistence on the server or where the attacker stole credentials during previous attacks.
See also: New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server
Microsoft released patches for on-premises Exchange systems on March 2. Four bugs had already been exploited by a state-sponsored hacking group called Hafnium.
Microsoft earlier this week said that 92% of the Exchange Server vulnerabilities had been patched or mitigated. However, cybersecurity firm F-Secure said that “tens of thousands” of Exchange Servers had already been compromised.
In a new post, Microsoft reiterated its warning that "patching a system does not necessarily remove the attacker's access.".
See also: Approximately 80,000 Exchange servers contain exploitable vulnerabilities!

“Many of the compromised systems have not yet been affected by other actions, such as ransomware attacks or data mining, indicating that the attackers could establish and maintain access for potential later actions,” notes the Microsoft 365 Defender Threat Intelligence Team.
For compromised systems, Microsoft urges administrators to implement the tactic of least privilege and mitigate lateral traffic on a network.
Least privilege will help address the method where an Exchange service, or a scheduled task, has been configured with a highly privileged account to perform tasks such as backups.
See also: DearCry ransomware: Targets unpatched Microsoft Exchange servers
Even in cases where victims have not been forced to pay a ransom, the attacker’s use of the xx.bat file allows them to explore a network via the web shell that originally deployed the file. The web shell also downloads the Cobalt Strike penetration testing kit before downloading the ransomware and encrypting files. In other words, a victim may not have been forced to pay a ransom today, but the attacker has the tools on their network to do so at a later time.
Microsoft has published several indicators of compromisethat network defenders can use to look for the presence of these threats and signs of credential theft.
