HomeSecurityMicrosoft Exchange: ProxyShell flaws exploited in crypto-mining attacks

Microsoft Exchange: ProxyShell flaws exploited in crypto-mining attacks

A new malware called ProxyShellMinerthat exploits vulnerabilities in Microsoft Exchange ProxyShell to install crypto-miners on victims' systems.

In this way, attackers can make money without consuming any power or wasting the available resources of their computers.

See also: Play ransomware: Exploited Microsoft Exchange exploit

Microsoft Exchange: ProxyShell flaws exploited in crypto-mining attacks
Microsoft Exchange: ProxyShell flaws found in crypto-mining attacks

ProxyShell refers to three vulnerabilities discovered and patched by Microsoft in 2021 Microsoft Exchange that, when combined, allow unauthorized RCE attacks . This allowed attackers to gain full control of the Exchange server , as well as move to other 'parts' of the network. In the attacks observed by Morphisec , hackers exploited the ProxyShell vulnerabilities (CVE-2021-34473) and (CVE-2021-34523) to gain initial access to the organization's network. To ensure that all devices within the network were running the malware, the attackers placed a malicious .NET payload in the NETLOGON folder of the Domain Controller . The malware requires a command line parameter that acts as a password to activate the 'XMRig' mining component . ProxyShellMiner uses an embedded dictionary, a decryption algorithm (XOR methodology) and an XOR key for the downloads (to follow) from a remote server and then uses a C# compiler with “InMemory” compilation parameters to execute the subsequent embedded code modules. In the next step, the malware downloads a file named “DC_DLL” and extracts the arguments for the task scheduler , XML and the XMRig key using a .NET reflection. The DLL file is used to decrypt additional files. See also: Scandinavian Airlines: Cyberattack led to data leak
 









Microsoft Exchange: ProxyShell flaws exploited in crypto-mining attacks
Microsoft Exchange: ProxyShell flaws found in crypto-mining attacks

A second downloader ensures that the malware remains on the infected system, creating a scheduled task that is set to run when the user logs in
. Next, the file chooses which browser to use to “invade” the crypto-miner into the memory space (of the browser), using “process hollowing” – then it selects a random mining pool from a hardcoded list and.. the mining begins!

The final step is to create a rule in the firewall that blocks all outgoing traffic.
This is done to make it less likely for the ‘defenders’ to detect signs of infection or receive notifications about a potential breach.
To bypass security tools that monitor the operation of processes, the malware waits at least 30 seconds after the browser is opened, before creating the above rule.

microsoft exchange flaws proxyshell mining crypto

Microsoft Exchange: ProxyShell flaws found in crypto-mining attacks

Morphisec warns that the impact of the malware goes beyond 'service outages', server performance degradation, and obvious computer overheating.
Once attackers gain access to the network, they can deploy backdoors and even execute code.

To reduce the risk of ProxyShellMiner infections, Morphisec recommends that all administrators run available updates and use comprehensive techniques for threat detection and defense.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS