Chinese hackers target Microsoft Exchange email servers to launch attacks

Zero-day attack
(Image credit: Shutterstock.com)

Security researchers have identified a “highly skilled and sophisticated” Chinese state-sponsored threat actor that’s using exploits in Microsoft Exchange to make away with confidential company data.

The Microsoft Threat Intelligence Center (MSTIC) detected multiple zero-day exploits in its flagship on-premise email server, which it said were primarily being used by the threat actor, dubbed Hafnium. The vulnerabilities have now been patched, and the software company urges all its business customers to update their Exchange server installations.

“Even though we’ve worked quickly to deploy an update for the Hafnium exploits, we know that many nation-state actors and criminal groups will move quickly to take advantage of any unpatched systems. Promptly applying today’s patches is the best protection against this attack,” suggests Tom Burt, Microsoft’s Corporate Vice President of Customer Security & Trust.

Not a first

According to Microsoft Hafnium primarily goes after targets in the United States. While it’s based in China, it uses leased Virtual Private Servers (VPS) in the US to run its malicious operations.

In a blog post, MSTIC notes that they’re aware of a limited number of targeted attacks that’ve used the now-patched Exchange vulnerabilities. 

Analyzing the modus operandi of the attacks, MSTIC says that “the threat actor used these vulnerabilities to access on-premises Exchange servers which enabled access to email accounts, and allowed installation of additional malware to facilitate long-term access to victim environments.”

Burt notes that this is the eighth attack by a state-sponsored group that the company has disclosed in the past twelve months. According to reports, the company has briefed and shared its findings about the attack with US Government agencies.

Via: TechCrunch

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
A padlock resting on a keyboard.
Massive botnet is targeting Microsoft 365 accounts across the world
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
China
Chinese hackers develop effective new hacking technique to go after business networks
Avast cybersecurity
An unpatched Windows zero-day flaw has been exploited by 11 nation-state attackers
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired