Ransomware Targets Tens of Thousands of Vulnerable Microsoft Exchange Servers
Hackers deploy DearCry ransomware on unprotected Microsoft Exchange servers using the same vulnerabilities exploited by a Chinese espionage group. Government agencies warn that thousands of organizations remain at high risk despite available security patches.
Hackers actively exploit recently discovered vulnerabilities in Microsoft Exchange email servers to deploy a new file-encrypting ransomware known as DearCry. Microsoft warns that this malicious software uses the same four security flaws previously linked to a China-backed espionage group called Hafnium, allowing attackers to take full control of vulnerable systems.
Security researchers report that at least 10 different hacking groups compromise Exchange servers, with infections spreading rapidly across the United States, Canada, and Australia. This ransomware wave emerges just days after a researcher published proof-of-concept exploit code online, making it easier for opportunistic criminals to launch destructive attacks.
Although the number of vulnerable servers drops from an initial 400,000 to roughly 82,000, hundreds of banks, healthcare companies, and over 150 U.S. federal government servers remain at risk. The FBI and CISA issue urgent warnings to businesses, noting that while Microsoft releases security patches, these updates do not remove hackers who already gained access to the systems.