Thousands of Organizations Still Vulnerable to Microsoft Exchange Server Hack
A Chinese state-sponsored hacking group exploits legacy on-premises Exchange servers to install web shells and prepare for future attacks. Despite available patches, many organizations remain exposed.
A Chinese state-sponsored hacking group known as Hafnium attacks on-premises versions of Microsoft Exchange Server using a series of zero-day exploits. The hackers target over 30,000 organizations in the United States, exploiting vulnerabilities collectively called ProxyLogon to access email accounts and install web shell malware. This malicious software gives the attackers ongoing administrative access to the compromised servers.
Microsoft releases security updates for Exchange Server versions 2010, 2013, 2016, and 2019 to address these critical flaws. However, research shows that plenty of unpatched systems remain active today. Analysts note that the attackers specifically target less mature organizations that still rely on legacy on-premises software instead of migrating to cloud-based Exchange, creating a fertile ground for cybercrime.
The ultimate goal of these hackers is not necessarily the compromised email servers themselves, but rather using them as a conduit to reach higher-value targets connected to those networks. By maintaining persistent access through web shells, the cybercriminals set the stage for more damaging future attacks, making it crucial for IT administrators to apply the available patches immediately.