{"id":58964,"date":"2021-03-15T11:10:21","date_gmt":"2021-03-15T11:10:21","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=58964"},"modified":"2021-03-15T11:10:22","modified_gmt":"2021-03-15T11:10:22","slug":"number-of-apt-groups-exploiting-the-latest-exchange-vulnerabilities-grows","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2021\/03\/15\/number-of-apt-groups-exploiting-the-latest-exchange-vulnerabilities-grows\/","title":{"rendered":"Number of APT groups exploiting the latest Exchange vulnerabilities grows"},"content":{"rendered":"\n<p>ESET Research has discovered that more than ten different advanced persistent threat (APT) groups are exploiting the recent Microsoft Exchange vulnerabilities to compromise email servers. ESET has identified more than 5,000 email servers that have been affected by malicious activity related to the incident.<\/p>\n\n\n\n<p>According to ESET, the servers belong to organisations \u2013 businesses and governments alike \u2013 from around the world, including high-profile ones. Thus, the threat is not limited to the widely reported Hafnium group.<\/p>\n\n\n\n<p>In early March, Microsoft released <a href=\"https:\/\/urldefense.proofpoint.com\/v2\/url?u=https-3A__msrc-2Dblog.microsoft.com_2021_03_02_multiple-2Dsecurity-2Dupdates-2Dreleased-2Dfor-2Dexchange-2Dserver_&amp;d=DwMFaQ&amp;c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&amp;r=-dhCLKDL2-MLjta9IhsAEyQseKloQxb6xFskIFoECtI&amp;m=a5DhhScl1IkEUSxSjAaW2alULwvyfhuCpLFXpUgpa0w&amp;s=ZKZC6c8rpMHM1abM2VJ0KTIzmr8L81CAby9DTCJhMGY&amp;e=\">patches<\/a> for Exchange Server 2013, 2016 and 2019 that fix a series of pre-authentication remote code execution (RCE) vulnerabilities. The vulnerabilities allow an attacker to take over any reachable Exchange server, without the need to know any valid account credentials, making internet-connected Exchange servers especially vulnerable.<\/p>\n\n\n\n<p>\u201cThe day after the release of the patches, we started to observe many more threat actors scanning and compromising Exchange servers en masse. Interestingly, all of them are APT groups focused on espionage, except one outlier that seems related to a known <a>coin-mining <\/a>campaign. However, it is inevitable that more and more threat actors, including ransomware operators, will have access to the exploits sooner or later,\u201d said Matthieu Faou, who is leading ESET\u2019s research effort into the recent Exchange vulnerability chain. \u201cESET researchers noticed that some APT groups were exploiting the vulnerabilities even before the patches were released. This means we can discard the possibility that those groups built an exploit by reverse engineering Microsoft updates.\u201d<\/p>\n\n\n\n<p>ESET telemetry flagged the presence of webshells (malicious programs or scripts that allow remote control of a server via a web browser) on more than 5,000 unique servers in over 115 countries.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ESET Research has discovered that more than ten different advanced persistent threat (APT) groups are exploiting the recent Microsoft Exchange vulnerabilities to compromise email servers. ESET has identified more than 5,000 email servers that have been affected by malicious activity related to the incident. According to ESET, the servers belong to organisations \u2013 businesses and [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":58965,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,36,54,13],"tags":[1062,314,13175],"class_list":["post-58964","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-intelligent-technology","category-research","category-top-stories","tag-apts","tag-eset","tag-microsoft-exchange-server"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/58964","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=58964"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/58964\/revisions"}],"predecessor-version":[{"id":58966,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/58964\/revisions\/58966"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/58965"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=58964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=58964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=58964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}