10 APT Groups Exploit Microsoft Exchange Security Flaws
At least 10 different advanced persistent threat (APT) groups in addition to China-linked Hafnium have been actively exploiting the recent Microsoft Exchange security flaws since Microsoft started fixing these email server vulnerabilities, according to threat researchers.
At least 10 different advanced persistent threat (APT) groups in addition to China-linked Hafnium have been actively exploiting the recent Microsoft Exchange security flaws since Microsoft started fixing these email server vulnerabilities, according to threat researchers.
ESET Research today identified the 10 APT groups and said these groups have compromised more than 5,000 Microsoft Exchange email servers in over 115 counties globally. “The servers belong to organizations — businesses and governments alike — from around the world, including high-profile ones,” the threat researchers wrote in a blog post. “Thus, the threat is not limited to the widely reported Hafnium group.”
In early March, Microsoft released patches for Exchange Server 2013, 2016, and 2019 that fix a series of pre-authentication remote code execution (RCE) vulnerabilities. The vulnerabilities allow an attacker to take over any reachable Exchange server, without the need to know any valid account credentials, making internet-connected Exchange servers especially vulnerable.
Since then, however, Hafnium “dramatically stepped up attacks” on unpatched systems, and earlier this week Microsoft issued patches for older, unsupported versions of its Exchange Server email software.
The 10 new APT groups are currently using the Microsoft Exchange security flaws for espionage and coin mining — but ransomware gangs are likely to follow, ESET warned.
“The day after the release of the patches, we started to observe many more threat actors scanning and compromising Exchange servers en masse,” said Matthieu Faou, who is leading ESET’s research effort. “Interestingly, all of them are APT groups focused on espionage, except one outlier that seems related to a known coin-mining campaign. However, it is inevitable that more and more threat actors, including ransomware operators, will have access to the exploits sooner or later.”
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), has urged all organization to immediately update their Microsoft Exchange Server email software and address the vulnerabilities.