Rackspace , a Texas-based cloud computing provider, has confirmed that the Play ransomware operation was behind a recent cyberattack that took down the company's hosted Microsoft Exchange environments
Last month, a report was released by cybersecurity firm Crowdstrike, which revealed a new exploit that ransomware gangs are using to compromise Microsoft Exchange servers and gain access to an organization's networks.
The new exploit, dubbed (OWASSRF), allows bypassing the ProxyNotShell provided by Microsoft, likely targeting the CVE-2022-41080 vulnerability that allows remote privilege escalation on Exchange servers.
They also managed to gain remote code execution on vulnerable servers by abusing CVE-2022-41082, the same bug that exploited the ProxyNotShell attacks.
See also: Twitter: 200 million users' emails leaked

While Crowdstrike itself did not name the victim of the attack in its report, Rackspace employees themselves spoke to local media about how the OWASSRF exploit was found on their network and that the Play ransomware operation was behind the cyberattack.
Rackspace's chief security officer, Karen O'Reilly-Smith, says that they are now confident that the root cause of the attack lies behind the zero-day vulnerability CVE-2022-41080 and that they will share all information with the company's customers and partners.
Customers after the attack received free licenses to migrate their emails from the Hosted Exchange platform to Microsoft 365.
Protect Exchange servers from Play ransomware attacks
CrowdStrike said the OWASSRF exploit was used to drop remote access tools, such as Plink and AnyDesk, onto compromised Rackspace servers. The Play ransomware also found ConnectWise, a remote administration tool that is likely involved in the attacks.
Organizations using on-premises Microsoft Exchange servers in their networks are urged to update to the latest version, with a minimum of November. Otherwise, another solution is to disable OWA (Outlook Web Access) until the patch for the vulnerability "CVE-2022-41080" is released.
The Play ransomware operation first appeared in June 2022.

Unlike other ransomware operations, members of the Play gang prefer to negotiate with victims via email and do not include links to a Tor negotiation page in the ransom notes.
However, before dropping the ransomware payloads, the hackers steal data from their victims' networks and threaten to release it online unless a ransom is paid.
Recent victims of the Play ransomware include the German hotel chain H-Hotels, the judicial authority of Cordoba, and the city of Antwerp in Belgium.
Source: bleepingcomputer.com
