HomeSecurityMicrosoft Exchange Server: Vulnerabilities exploited to distribute keylogger

Microsoft Exchange Server: Vulnerabilities exploited to distribute keylogger

Hackers are exploiting known vulnerabilities in Microsoft Exchange Server to deploy keylogger malware, in attacks targeting entities in Africa and the Middle East.

Microsoft Exchange Server keylogger vulnerabilities

Positive Technologies identified more than 30 victims in government agencies, banks, IT companies and educational institutions. The attacks date back to 2021. The victims were mainly located in the following regions: UAE, Kuwait, Oman, Niger, Nigeria, Ethiopia, Mauritius, Jordan, Lebanon, Russia.

See also: Veeam warns of critical vulnerability in VBEM

“The keylogger collected account credentials in a file accessible via a special path from the Internet,” the company said in a recent report.

How are attacks carried out?

The attacks begin by exploiting ProxyShell (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) that were patched by Microsoft in May 2021.

Successful exploitation of the vulnerabilities allows an attacker to bypass authentication, gain increased privileges on the vulnerable system, and perform remote code execution.

After exploiting the vulnerabilities, hackers add the keylogger malware to the server's main page (“logon.aspx”) and insert code that collects credentials into a file accessible from the Internet (by clicking the login button).

Positive Technologies said that, at this time, it cannot attribute the attacks to any known threat group.

See also: Vulnerability in Python package for AI models and PDF.js

To stay protected organizationsshould update their Microsoft Exchange Server instances to the latest version. Additionally, administrators should look for potential signs of compromise in the Exchange Server main page, including the clkLgn() function where the keylogger is inserted.

“If your server has been compromised, locate the stolen account data and delete the file where this data is stored by the hacker,” the company said. “You can find the path to this file in the logon.aspx file.”

Microsoft Exchange Server: Vulnerabilities exploited to distribute keylogger
Microsoft Exchange Server: Vulnerabilities exploited to distribute keylogger

Protection from vulnerabilities

Staff awareness and training are crucial. Employees need to be aware of the risks associated with cybersecurity and good practices for avoiding attacks.

Using advanced security solutions, such as intrusion protection systems (IPS), intrusion detection systems (IDS), and antivirus, can help counter attacks and protect against errors.

Applying updates is one of the most effective ways to protect against security vulnerabilities . Attackers often exploit known vulnerabilities in older versions of software to distribute malware, including keyloggers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: QNAP QTS: 15 vulnerabilities found – PoC exploit available for one of them

Using multi-factor authentication (MFA) can provide an extra layer of protection, as it requires users to provide two or more verification elements to prove identity .

Finally, creating and implementing an information security policy can prevent the exploitation of vulnerabilities. This policy should include protection , system and network protection, and response to security breaches.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS