• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
ms exchange server flaws exploited to deploy keylogger in targeted

MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted Attacks

You are here: Home / General Cyber Security News / MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted Attacks
May 22, 2024

An not known menace actor is exploiting recognized security flaws in Microsoft Trade Server to deploy a keylogger malware in attacks concentrating on entities in Africa and the Center East.

Russian cybersecurity company Constructive Systems explained it discovered around 30 victims spanning govt companies, financial institutions, IT firms, and instructional establishments. The to start with-ever compromise dates again to 2021.

“This keylogger was collecting account qualifications into a file accessible by means of a exclusive path from the internet,” the organization explained in a report released past week.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


International locations qualified by the intrusion set consist of Russia, the U.A.E., Kuwait, Oman, Niger, Nigeria, Ethiopia, Mauritius, Jordan, and Lebanon.

Cybersecurity

The attack chains start with the exploitation of ProxyShell flaws (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) that ended up at first patched by Microsoft in May possibly 2021.

Productive exploitation of the vulnerabilities could make it possible for an attacker to bypass authentication, elevate their privileges, and have out unauthenticated, remote code execution. The exploitation chain was uncovered and printed by Orange Tsai from the DEVCORE Investigation Workforce.

MS Exchange Server Flaws

The ProxyShell exploitation is adopted by the risk actors incorporating the keylogger to the server main webpage (“logon.aspx”), in addition to injecting code liable for capturing the qualifications to a file obtainable from the internet upon clicking the sign in button.

Favourable Systems reported it are unable to attribute the attacks to a recognised threat actor or group at this stage without the need of supplemental details.

Cybersecurity

Beside updating their Microsoft Trade Server circumstances to the most recent version, corporations are urged to appear for opportunity indications of compromise in the Exchange Server’s key webpage, including the clkLgn() operate where the keylogger is inserted.

“If your server has been compromised, identify the account info that has been stolen and delete the file where this details is stored by hackers,” the corporation claimed. “You can locate the path to this file in the logon.aspx file.”

Located this post appealing? Stick to us on Twitter  and LinkedIn to read through a lot more distinctive articles we submit.


Some elements of this write-up are sourced from:
thehackernews.com

Previous Post: «qnap patches new flaws in qts and quts hero impacting QNAP Patches New Flaws in QTS and QuTS hero Impacting NAS Appliances
Next Post: GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking Attack ghostengine exploits vulnerable drivers to disable edrs in cryptojacking attack»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)
  • PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution
  • Securing Data in the AI Era
  • Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild
  • Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals
  • CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises
  • Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads
  • Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord
  • Four Arrested in £440M Cyber Attack on Marks & Spencer, Co-op, and Harrods
  • What Security Leaders Need to Know About AI Governance for SaaS

Copyright © TheCyberSecurity.News, All Rights Reserved.