HomeSecurityHackers steal Microsoft Exchange credentials using IIS module

Hackers steal Microsoft Exchange credentials using IIS module

Threat actors install a malicious IIS web server module named “Owowa” on Microsoft Exchange Outlook Web Access servers to steal credentials and execute commands on the server remotely.

Owowa's development likely began in late 2020 based on the data collected and uploaded to the malware scanning service VirtusTotal.

Based on Kaspersky's telemetry data, the most recent sample in circulation is from April 2021, targeting servers in Malaysia, Mongolia, Indonesia, and the Philippines.

See also: Patch Tuesday December 2021: Microsoft fixes 67 vulnerabilities

These systems belong to government agencies, public transportation companies, and other critical entities.

Kaspersky emphasizes that "Owowa" targets are not limited to Southeast Asia and has seen signs of infections in Europe as well.

Hackers steal Microsoft Exchange credentials using IIS module

An unusual backdoor

Microsoft Exchange servers are commonly targeted with web shells that allow threat actors to remotely execute commands on a server and are usually the focus of defenders.

Therefore, using an IIS module as a backdoor is a great way to stay hidden. Hackers can send seemingly harmless authentication requests to OWA, avoiding standard network monitoring rules.

Furthermore, the implant persists even after the Exchange software is updated, so the infection only needs to occur once.

See also: Microsoft: Patches Windows AppX Installer zero-day exploited by Emotet

Kaspersky comments that the hacker may rely on flaws in ProxyLogon to compromise the server, which remains a problem even after the patch update nine months ago.

However, the hackers didn't do a perfect job with Owowa's deployment, failing to hide the PDB paths in the malware executable and causing server crashes in some cases.

Features

Owowa specifically targets OWA applications on Exchange servers and is designed to capture the credentials of users who successfully authenticate to the OWA login page.

Login success is automatically validated by monitoring the OWA application for the generation of an authentication token.

Microsoft Exchange

If this happens, Owowa stores the username, password, user IP address, and current timestamp and encrypts the data using RSA.

The hacker can then collect the stolen data by manually sending a command to the malicious module.

Remote commands can be used to execute PowerShell on the compromised endpoint, opening the way to a range of attack possibilities.

See also: QBot malware: Microsoft analyzes the building blocks of attacks

Locate and remove the IIS module

Administrators can use the IIS configuration tool to get a list of all loaded modules on an IIS server.

In the cases seen by the researchers, the malicious module uses the name “ExtenderControlDesigner”, as shown below.

Microsoft Exchange

Although researchers were led to an account on the hacking forum RaidForums during the investigation, the performance remains weak and there are generally no associations with known hackers.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS