HomeSecurityFIN7: Created an auto-attack platform to compromise Exchange servers

FIN7: Created an auto-attack platform to compromise Exchange servers

The notorious FIN7 hacking group uses an automated attack system that exploits Microsoft Exchange and SQL injection vulnerabilities to breach corporate networks, steal data, and select targets for ransomware attacks based on financial size.

FIN7

Prodaft's threat intelligence team has been monitoring the FIN7 group's operations for many years and finally uncovered this system.

See also: Zerobot malware now spreads by exploiting Apache vulnerabilities

Before its release, Prodaft revealed information in a report to BleepingComputer about FIN7's internal hierarchy, connections to multiple ransomware programs, and a clever SSH backdoor system implemented to steal confidential documents from network breaches.

Since 2012, FIN7 has been an active Russian-speaking criminal group with the sole motive of financial gain.

They have been associated with ATM attacks, the creation of fake cybersecurity companies to recruit attackers for ransomware attacks, and more.

Auto-attack platform for Microsoft Exchange

The innovative auto-attack system “Checkmarks” is a powerful tool for scanning for remote code execution and privilege escalation vulnerabilities in Microsoft Exchange, such as CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207.

In June 2021, FIN7 began leveraging Checkmarks to quickly identify weak spots in companies' networks and breach them using PowerShell to drop web shells

FIN7 leveraged a range of exploits to penetrate target networks, including their own custom code and publicly available PoCs.

See also: Hackers steal large quantities of food and sell it on the dark web

In addition to the MS Exchange flaws, the Checkmarks attack platform also features a SQL injection module that uses SQLMap to scan for potentially exploitable flaws on a target's website.

FIN7

After the initial attack phase, Checkmarks quickly performs post-exploitation processes, such as extracting emails from Active Directory and collecting data from Exchange servers.

FIN7: Created an auto-attack platform to compromise Exchange servers

When new victims are detected, they are quickly integrated into a central dashboard for FIN7 operators to see more information about the affected endpoint.

FIN7

FIN7's internal "marketing" team then reviews all new listings and adds comments to the Checkmarks platform, in order to record the victim's revenue, number of staff members, domain, headquarters details and other useful information that can help pentesters decide whether or not it is worth attacking this company.

See also: Knox College ransomware: Hackers demand ransom from students

When it comes to assessing a company’s size and financial health, FIN7’s marketing team conducts exhaustive due diligence. They use a range of trusted sources for their research, including Owler, Crunchbase, DNB, Zoominfo, Mustat, and Similarweb.

FIN7: Created an auto-attack platform to compromise Exchange servers

Prodaft says that FIN7's Checkmarks platform has already been used for attacks on 8,147 companies, mostly based in the United States (16.7%), after scanning over 1.8 million targets.

FIN7: Created an auto-attack platform to compromise Exchange servers

In conclusion, it is clear that FIN7 is one of the most dangerous cybercriminal organizations out there today and should not be taken lightly by any business owner or consumer. Their sophisticated tactics make them a formidable opponent for any organization that does not have strong security measures in place – however, by remaining vigilant and taking proactive steps to improve your cybersecurity posture – such as deploying antivirus software and training employees on proper email security protocols – you can drastically reduce the chances of falling victim to a FIN7 hack attack.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS