Chinese Cyber Espionage Group Hacks 30,000 US Organizations via Microsoft Exchange Flaws

A Chinese hacking group known as Hafnium exploits newly discovered Microsoft Exchange Server vulnerabilities to compromise tens of thousands of US organizations. The attackers install web shells on victim servers to maintain persistent remote control and steal sensitive email communications.

An aggressive Chinese cyber espionage group known as Hafnium hacks at least 30,000 organizations across the United States, including small businesses, towns, and local governments. The attackers exploit four newly discovered vulnerabilities in Microsoft Exchange Server email software to steal communications from victim networks. Security experts report that this campaign compromises hundreds of thousands of Microsoft Exchange Servers worldwide.

Microsoft releases emergency security updates on March 2 to patch these flaws in Exchange Server versions 2013 through 2019, but the hacking group dramatically escalates its attacks in the days following the patch. The Chinese cyber espionage unit initially targets specific sectors like infectious disease researchers, law firms, higher education institutions, and defense contractors. However, the attackers quickly shift to a much broader strategy that targets any vulnerable, unpatched Exchange server globally.

In each successful intrusion, the hackers leave behind a web shell, which is a password-protected hacking tool accessible from any web browser. This malicious tool gives the attackers ongoing administrative access to the victim's computer servers. Security researchers note that this quiet exploitation actually begins on January 6, 2021, but rapidly evolves into a highly aggressive, mass-hacking operation over the past few days.

Read More at the original source →