The FBI is warning that a vulnerability in Zoho's ManageEngine Desktop Central is being exploited by government-backed hackers (these hacking groups are also known as APTs).
“ Since at least late October 2021, hackers from APT groups have been exploiting the zero-day bug, known as CVE-2021-44515, and detected in ManageEngine Desktop Central servers ,” the FBI said
See also: Log4j Log4Shell vulnerability used to install Dridex banking trojan

“Hackers were identified who were compromising Desktop Central servers by installing a webshell that bypasses a legitimate Desktop Central function, downloading post-exploitation tools, performing network reconnaissance, attempting lateral movement, and stealing credentials“.
The zero-day vulnerability was patched by Zoho in early December. It is a critical “authentication bypass vulnerability” that could be exploited by criminals to execute code on vulnerable Desktop Central servers.
CISA also identified the vulnerability as critical and has asked federal agencies to update their systems before Christmas.
See also: Belgian Ministry of Defense: Confirms cyberattack via Log4j
Customers were asked to update their systems
After releasing the patch to fix the zero-day vulnerability, Zoho warned customers about ongoing attempts to exploit the bug, and urged them to immediately deploy security updates to stay protected.
To detect if your server was compromised via this zero-day vulnerability, you can use Zoho's Exploit Detection Tool and follow the steps described here.

The company also recommends backing up critical business data, disconnecting affected network systems, formatting all compromised servers, restoring Desktop Central, and updating to the latest version.
See also: Microsoft fixes two Active Directory bugs
If signs of a breach are found, Zoho recommends resetting passwords “for all affected services, accounts, Active Directory, etc.”, along with Active Directory administrator passwords.
According to Shodan, there are over 2,900 ManageEngine Desktop Central instances that are vulnerable to attacks.
Source: Bleeping Computer
