Hackers are exploiting known vulnerabilities in Microsoft Exchange Server to deploy keylogger malware, in attacks targeting entities in Africa and the Middle East.

Positive Technologies identified more than 30 victims in government agencies, banks, IT companies and educational institutions. The attacks date back to 2021. The victims were mainly located in the following regions: UAE, Kuwait, Oman, Niger, Nigeria, Ethiopia, Mauritius, Jordan, Lebanon, Russia.
See also: Veeam warns of critical vulnerability in VBEM
“The keylogger collected account credentials in a file accessible via a special path from the Internet,” the company said in a recent report.
How are attacks carried out?
The attacks begin by exploiting ProxyShell (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) that were patched by Microsoft in May 2021.
Successful exploitation of the vulnerabilities allows an attacker to bypass authentication, gain increased privileges on the vulnerable system, and perform remote code execution.
After exploiting the vulnerabilities, hackers add the keylogger malware to the server's main page (“logon.aspx”) and insert code that collects credentials into a file accessible from the Internet (by clicking the login button).
Positive Technologies said that, at this time, it cannot attribute the attacks to any known threat group.
See also: Vulnerability in Python package for AI models and PDF.js
To stay protected organizationsshould update their Microsoft Exchange Server instances to the latest version. Additionally, administrators should look for potential signs of compromise in the Exchange Server main page, including the clkLgn() function where the keylogger is inserted.
“If your server has been compromised, locate the stolen account data and delete the file where this data is stored by the hacker,” the company said. “You can find the path to this file in the logon.aspx file.”

Protection from vulnerabilities
Staff awareness and training are crucial. Employees need to be aware of the risks associated with cybersecurity and good practices for avoiding attacks.
Using advanced security solutions, such as intrusion protection systems (IPS), intrusion detection systems (IDS), and antivirus, can help counter attacks and protect against errors.
Applying updates is one of the most effective ways to protect against security vulnerabilities . Attackers often exploit known vulnerabilities in older versions of software to distribute malware, including keyloggers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: QNAP QTS: 15 vulnerabilities found – PoC exploit available for one of them
Using multi-factor authentication (MFA) can provide an extra layer of protection, as it requires users to provide two or more verification elements to prove identity .
Finally, creating and implementing an information security policy can prevent the exploitation of vulnerabilities. This policy should include protection , system and network protection, and response to security breaches.
Source: thehackernews.com
