Microsoft reports that BlackCat ransomware is now attacking Exchange servers using vulnerabilities that target unpatched vulnerabilities.
In at least one incident observed by Microsoft security experts, attackers slowly moved through the victim's network, stealing credentials and infiltrating information to use for double blackmail.

Two weeks after the initial compromise using unpatched Exchange servers as an entry point, the hackers deployed BlackCat ransomware payloads across the network via PsExec. “While common access points for these hackers include remote desktop applications and compromised credentials, we also saw a hacker exploit server to gain access to the target network,” said the Microsoft 365 Defender Threat Intelligence team.
While it did not mention the Exchange vulnerability used for initial access, Microsoft linked it to a security advisory from March 2021 with guidance on investigating and mitigating ProxyLogon attacks. Also, while Microsoft did not name who is behind the BlackCat ransomware in this case, the company says that several cybercrime groups are using the Ransomware as a Service (Raas) feature and are actively using it in attacks.
Cybercriminals flock to BlackCat ransomware
One of them, a financially motivated cybercrime group tracked as FIN12, is known for deploying the Ryuk, conti , and Hive Ransomware in attacks primarily targeting healthcare organizations.
However, as Mandiant, FIN12s are much faster as they sometimes skip the data theft step and take less than two days to drop file encryption payloads on a target's network.
“We observed that this group added BlackCat to the list of distributed payloads since March 2022,” Microsoft added.
“Their move to BlackCat from the last payload used (Hive) is speculated to be due to the public debate surrounding the latter’s decryption methodologies.”

BlackCat ransomware is also being developed by a group tracked as DEV-0504 that typically uses stolen data via Stealbit, a malicious tool that the LockBit to its partners as part of its RaaS program. DEV-0504 has also used other ransomware strains starting in December 2021, including BlackMatter, Conti, LockBit 2.0, Revil, and Ryuk.
To defend against BlackCat ransomware attacks, Microsoft advises organizations to check for strange behavior, monitor external access to their networks, and update all vulnerable Exchange servers in their environment as soon as possible.
Used in hundreds of ransomware attacks
In April, the FBI warned in a rapid alert that BlackCat ransomware had been used to encrypt the networks of at least 60 organizations worldwide between November 2021 and March 2022.
“Many of the developers for BlackCat/ALPHV are affiliated with Darkside/Blackmatter, indicating they have extensive networks and experience with ransomware operations,” the FBI said at the time.
However, the actual number of BlackCart victims is likely much higher, given that more than 480 samples have been submitted to the ID-Ransomware between November 2021 and June 2022.
