State-Sponsored Hackers Exploit Unpatched Microsoft Exchange Servers

A Chinese hacking group known as Hafnium attacks thousands of organizations using Microsoft Exchange Server vulnerabilities called ProxyLogon. Many legacy systems remain unpatched, leaving less mature businesses vulnerable to ongoing cyber threats.

Microsoft detects multiple zero-day exploits attacking on-premises versions of Microsoft Exchange Server, with over 30,000 US organizations falling victim in early March 2021. Hackers use these vulnerabilities, collectively known as ProxyLogon, to access email accounts and install web shell malware for ongoing administrative control. Microsoft attributes these attacks to Hafnium, a state-sponsored Chinese hacking group that primarily targets US organizations across various industries using leased virtual private servers.

The attackers specifically target organizations that still rely on older, on-premises Exchange platforms rather than modern cloud solutions. Analysts note that these late-adopting organizations often lack specialized IT administrators and pay little attention to legacy software updates, creating a fertile ground for cybercriminals. Microsoft releases emergency updates for Exchange Server versions 2010, 2013, 2016, and 2019 to address the four critical vulnerabilities involved in these breaches.

Despite the availability of these security patches, research shows that plenty of unpatched systems remain active today as organizations battle to close the holes. Hackers use these compromised servers not as final targets, but as conduits to launch future attacks against higher-value connected networks. Microsoft continues to urge IT administrators to prioritize patching and audit their systems for existing web shells to prevent further network compromise.

Read More at the original source →