https://krebsonsecurity.com/2021/03/microsoft-chinese-cyberspies-used-4-exchange-server-flaws-to-plunder-emails/ Advertisement RSS Feed Subscribe to RSS Twitter Follow me on Twitter Facebook Join me on Facebook [47] Krebs on Security In-depth security news and investigation Brian Krebs About the Author Advertising/Speaking --------------------------------------------------------------------- 02 Mar 21 Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder Emails Microsoft Corp. today released software updates to plug four security holes that attackers have been using to plunder email communications at companies that use its Exchange Server products. The company says all four flaws are being actively exploited as part of a complex attack chain deployed by a previously unidentified Chinese cyber espionage group. [exchange] The software giant typically releases security updates on the second Tuesday of each month, but it occasionally deviates from that schedule when addressing active attacks that target newly identified and serious vulnerabilities in its products. The patches released today fix security problems in Microsoft Exchange Server 2013, 2016 and 2019. Microsoft said its Exchange Online service -- basically hosted email for businesses -- is not impacted by these flaws. Microsoft credited researchers at Reston, Va. based Volexity for reporting the attacks. Volexity President Steven Adair told KrebsOnSecurity it first spotted the attacks on Jan. 6, 2021. Adair said while the exploits used by the group may have taken great skills to develop, they require little technical know-how to use and can give an attacker easy access to all of an organization's email if their vulnerable Exchange Servers are directly exposed to the Internet. "These flaws are very easy to exploit," Adair said. "You don't need any special knowledge with these exploits. You just show up and say 'I would like to break in and read all their email.' That's all there is to it." Microsoft says the flaws are being used by a previously unknown Chinese espionage group that's been dubbed "Hafnium," which is known to launch its attacks using hosting companies based in the United States. "Hafnium primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs," Microsoft said. "HAFNIUM has previously compromised victims by exploiting vulnerabilities in internet-facing servers. Once they've gained access to a victim network, HAFNIUM typically exfiltrates data to file sharing sites like MEGA." According to Microsoft, Hafnium attackers have been observed combining all four zero-day flaws to target organizations running vulnerable Exchange Server products. CVE-2021-26855 is a "server-side request forgery" (SSRF) flaw, in which a server (in this case, an on-premises Exchange Server) can be tricked into running commands that it should never have been permitted to run, such as authenticating as the Exchange server itself. The attackers used CVE-2021-26857 to run code of their choice under the "system" account on a targeted Exchange server. The other two zero-day flaws -- CVE-2021-26858 and CVE-2021-27065 -- could allow an attacker to write a file to any part of the server. After exploiting these vulnerabilities to gain initial access, Hafnium operators deployed web shells on the compromised server, Microsoft said. Web shells are essentially software backdoors that allow attackers to steal data and perform additional malicious actions that lead to further compromise. Neither Microsoft nor Volexity is aware of publicly available code that would allow other cybercriminals to exploit these Exchange vulnerabilities. But given that these attacks are in the wild now, it may only be a matter of days before exploit code is publicly available online. Microsoft stressed that the exploits detailed today were in no way connected to the separate SolarWinds-related attacks. "We continue to see no evidence that the actor behind SolarWinds discovered or exploited any vulnerability in Microsoft products and services," the company said. Further reading: Microsoft's writeup on new Hafnium nation state cyberattacks Microsoft technical advisory on the four Exchange Server flaws [92] Tags: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, Hafnium, Microsoft Exchange, zero day This entry was posted on Tuesday, March 2nd, 2021 at 4:19 pm and is filed under Latest Warnings, The Coming Storm, Time to Patch. You can follow any comments to this entry through the RSS 2.0 feed. You can skip to the end and leave a comment. Pinging is currently not allowed. One comment 1. [afc7] E.M.H. March 2, 2021 at 5:16 pm Microsoft's documentation on this is pretty good: They've listed IoCs, descriptions of the activities seen, detection scripts for Azure hosted Exchange, etc. The CVSS score for the SSRF vulnerability is a 9.1. Ouch. That one's a "I'm going to be late for dinner tonight" patch for Exchange service administrators. It's not great that this flaw was present, but it looks like it's being addressed as well as it can be. That's a good thing. Reply Leave a comment Click here to cancel reply. Name (required)[ ] Email (required)[ ] Website[ ] Comment [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [Submit Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] Advertisement [46] * [ ] [search_mag] [96] * Mailing List Subscribe here * Recent Posts + Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder Emails + Payroll/HR Giant PrismHR Hit by Ransomware? + Is Your Browser Extension a Botnet Backdoor? + How $100M in Jobless Claims Went to Inmates + Checkout Skimmers Powered by Chip Cards * * All About Skimmers All About Skimmers Click image for my skimmer series. * Donate to Krebs On Security * Spam Nation Spam Nation A New York Times Bestseller! * * The Value of a Hacked PC valuehackedpc Badguy uses for your PC * Tools for a Safer PC Tools for a Safer PC Tools for a Safer PC * The Pharma Wars The Pharma Wars Spammers Duke it Out * Badguy Uses for Your Email Badguy Uses for Your Email Your email account may be worth far more than you imagine. * eBanking Best Practices eBanking Best Practices eBanking Best Practices for Businesses * Most Popular Posts + Sextortion Scam Uses Recipient's Hacked Passwords (1076) + Online Cheating Site AshleyMadison Hacked (798) + Sources: Target Investigating Data Breach (620) + Trump Fires Security Chief Christopher Krebs (534) + Cards Stolen in Target Breach Flood Underground Markets (445) + Reports: Liberty Reserve Founder Arrested, Site Shuttered (416) + Was the Ashley Madison Database Leaked? (376) + DDoS-Guard To Forfeit Internet Space Occupied by Parler (374) + True Goodbye: 'Using TrueCrypt Is Not Secure' (363) + Who Hacked Ashley Madison? (361) * Category: Web Fraud 2.0 Criminnovations Innovations from the Underground * [shreddedID-copy-285x189] ID Protection Services Examined * Is Antivirus Dead? Is Antivirus Dead? The reasons for its decline * The Growing Tax Fraud Menace The Growing Tax Fraud Menace File 'em Before the Bad Guys Can * Inside a Carding Shop Inside a Carding Shop A crash course in carding. * Beware Social Security Fraud Beware Social Security Fraud Sign up, or Be Signed Up! * How Was Your Card Stolen? How Was Your Card Stolen? Finding out is not so easy. * Krebs's 3 Rules... Krebs's 3 Rules... ...For Online Safety. --------------------------------------------------------------------- (c) 2021 Krebs on Security. Powered by WordPress. Privacy Policy