Threat actors install a malicious IIS web server module named “Owowa” on Microsoft Exchange Outlook Web Access servers to steal credentials and execute commands on the server remotely.
Owowa's development likely began in late 2020 based on the data collected and uploaded to the malware scanning service VirtusTotal.
Based on Kaspersky's telemetry data, the most recent sample in circulation is from April 2021, targeting servers in Malaysia, Mongolia, Indonesia, and the Philippines.
See also: Patch Tuesday December 2021: Microsoft fixes 67 vulnerabilities
These systems belong to government agencies, public transportation companies, and other critical entities.
Kaspersky emphasizes that "Owowa" targets are not limited to Southeast Asia and has seen signs of infections in Europe as well.

An unusual backdoor
Microsoft Exchange servers are commonly targeted with web shells that allow threat actors to remotely execute commands on a server and are usually the focus of defenders.
Therefore, using an IIS module as a backdoor is a great way to stay hidden. Hackers can send seemingly harmless authentication requests to OWA, avoiding standard network monitoring rules.
Furthermore, the implant persists even after the Exchange software is updated, so the infection only needs to occur once.
See also: Microsoft: Patches Windows AppX Installer zero-day exploited by Emotet
Kaspersky comments that the hacker may rely on flaws in ProxyLogon to compromise the server, which remains a problem even after the patch update nine months ago.
However, the hackers didn't do a perfect job with Owowa's deployment, failing to hide the PDB paths in the malware executable and causing server crashes in some cases.
Features
Owowa specifically targets OWA applications on Exchange servers and is designed to capture the credentials of users who successfully authenticate to the OWA login page.
Login success is automatically validated by monitoring the OWA application for the generation of an authentication token.

If this happens, Owowa stores the username, password, user IP address, and current timestamp and encrypts the data using RSA.
The hacker can then collect the stolen data by manually sending a command to the malicious module.
Remote commands can be used to execute PowerShell on the compromised endpoint, opening the way to a range of attack possibilities.
See also: QBot malware: Microsoft analyzes the building blocks of attacks
Locate and remove the IIS module
Administrators can use the IIS configuration tool to get a list of all loaded modules on an IIS server.
In the cases seen by the researchers, the malicious module uses the name “ExtenderControlDesigner”, as shown below.

Although researchers were led to an account on the hacking forum RaidForums during the investigation, the performance remains weak and there are generally no associations with known hackers.
Information source: bleepingcomputer.com
