HomeSecurityMicrosoft Exchange: Reply-chain attacks breached its servers

Microsoft Exchange: Reply-chain attacks breached its servers

Malicious actors have compromised Microsoft Exchange servers, using ProxyShell and ProxyLogon, to distribute malware and bypass detection, using stolen internal mail messages.

Microsoft Exchange

See also: Microsoft Exchange: New feature automatically mitigates high-risk bugs

TrendMicro researchers have discovered an interesting tactic used to distribute malicious emails to internal users of a company, using Microsoft Exchange servers that have been compromised by the victim themselves.

The hackers behind this attack are believed to be “TR,” a well-known hacking group that distributes emails with malicious attachments, which distribute malware, including Qbot, IcedID, Cobalt Strike , and SquirrelWaffle.

As a way to trick corporate targets into opening malicious attachments, the group exploits Microsoft Exchange servers, using the ProxyShell and ProxyLogon vulnerabilities.

Malicious actors then use these compromised Exchange servers to reply to internal company emails in reply-chain attacks containing links to malicious documents that install various malware.

See also: Microsoft Exchange Autodiscover: Bugs leak Windows credentials

As these emails originate from the same internal network and appear to be a continuation of a previous conversation between two employees, they lead to a greater degree of confidence that the email is legitimate and secure.

servers

Not only is it effective against humans, but it is also excellent at not raising any alarms in the email protection systems used at the target company.

The attachments provided or linked to in these emails are the typical malicious Microsoft Excel that tell recipients to “Enable Content” to view a protected file.

However, once the user activates the content, malicious macros are executed to download and install the malware distributed by the attachment, whether it is Qbot, Cobalt Strike, SquirrelWaffle, or other malware.

According to Trend Micro's report, researchers said they saw these attacks distributing SquirrelWaffle, which then installs Qbot.

Microsoft has patched the ProxyLogon vulnerabilities in March and the ProxyShell vulnerability in April and May, treating them as zero-days.

See also: FBI: Sophisticated group exploits a zero-day in FatPipe VPNs

Malicious actors have abused both vulnerabilities to deploy ransomware or install webshells for later backdoor access. The ProxyLogon attacks became so bad that the FBI removed webshells from compromised Microsoft Exchange servers based in the US without first notifying the owners of the servers.

After so long, not fixing Exchange servers is just an open invitation to hackers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS