https://krebsonsecurity.com/2021/03/at-least-30000-u-s-organizations-newly-hacked-via-holes-in-microsofts-email-software/ Advertisement RSS Feed Subscribe to RSS Twitter Follow me on Twitter Facebook Join me on Facebook [12] Krebs on Security In-depth security news and investigation Brian Krebs About the Author Advertising/Speaking --------------------------------------------------------------------- 05 Mar 21 At Least 30,000 U.S. Organizations Newly Hacked Via Holes in Microsoft's Email Software At least 30,000 organizations across the United States -- including a significant number of small businesses, towns, cities and local governments -- have over the past few days been hacked by an unusually aggressive Chinese cyber espionage unit that's focused on stealing email from victim organizations, multiple sources tell KrebsOnSecurity. The espionage group is exploiting four newly-discovered flaws in Microsoft Exchange Server email software, and has seeded hundreds of thousands of victim organizations worldwide with tools that give the attackers total, remote control over affected systems. [exchange] On March 2, Microsoft released emergency security updates to plug four security holes in Exchange Server versions 2013 through 2019 that hackers were actively using to siphon email communications from Internet-facing systems running Exchange. In the three days since then, security experts say the same Chinese cyber espionage group has dramatically stepped up attacks on any vulnerable, unpatched Exchange servers worldwide. In each incident, the intruders have left behind a "web shell," an easy-to-use, password-protected hacking tool that can be accessed over the Internet from any browser. The web shell gives the attackers administrative access to the victim's computer servers. Speaking on condition of anonymity, two cybersecurity experts who've briefed U.S. national security advisors on the attack told KrebsOnSecurity the Chinese hacking group thought to be responsible has seized control over "hundreds of thousands" of Microsoft Exchange Servers worldwide -- with each victim system representing approximately one organization that uses Exchange to process email. Microsoft said the Exchange flaws are being targeted by a previously unidentified Chinese hacking crew it dubbed "Hafnium," and said the group had been conducting targeted attacks on email systems used by a range of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. Microsoft's initial advisory about the Exchange flaws credited Reston, Va. based Volexity for reporting the vulnerabilities. Volexity President Steven Adair said the company first saw attackers quietly exploiting the Exchange bugs on Jan. 6, 2021, a day when most of the world was glued to television coverage of the riot at the U.S. Capitol. But Adair said that over the past few days the hacking group has shifted into high gear, moving quickly to scan the Internet for Exchange servers that weren't yet protected by the security updates Microsoft released Tuesday. "We've worked on dozens of cases so far where web shells were put on the victim system back on Feb. 28 [before Microsoft announced its patches], all the way up to today," Adair said. "Even if you patched the same day Microsoft published its patches, there's still a high chance there is a web shell on your server. The truth is, if you're running Exchange and you haven't patched this yet, there's a very high chance that your organization is already compromised." Reached for comment, Microsoft said it is working closely with the U.S. Cybersecurity & Infrastructure Security Agency (CISA), other government agencies, and security companies, to ensure it is providing the best possible guidance and mitigation for its customers. "The best protection is to apply updates as soon as possible across all impacted systems," a Microsoft spokesperson said in a written statement. "We continue to help customers by providing additional investigation and mitigation guidance. Impacted customers should contact our support teams for additional help and resources." Meanwhile, CISA has issued an emergency directive ordering all federal civilian departments and agencies running vulnerable Microsoft Exchange servers to either update the software or disconnect the products from their networks. Adair said he's fielded dozens of calls today from state and local government agencies that have identified the backdoors in their Exchange servers and are pleading for help. The trouble is, patching the flaws only blocks the four different ways the hackers are using to get in. But it does nothing to undo the damage that may already have been done. [chriskrebstweet] A tweet from Chris Krebs, former director of the Cybersecurity & Infrastructure Security Agency, responding to a tweet from White House National Security Advisor Jake Sullivan. White House press secretary Jen Psaki told reporters today the vulnerabilities found in Microsoft's widely used Exchange servers were "significant," and "could have far-reaching impacts." "We're concerned that there are a large number of victims," Psaki said. By all accounts, rooting out these intruders is going to require an unprecedented and urgent nationwide clean-up effort. Adair and others say they're worried that the longer it takes for victims to remove the backdoors, the more likely it is that the intruders will follow up by installing additional backdoors, and perhaps broadening the attack to include other portions of the victim's network infrastructure. Security researchers have published several tools for detecting vulnerable servers. One of those tools, a script from Microsoft's Kevin Beaumont, is available from Github. KrebsOnSecurity has seen portions of a victim list compiled by running such a tool, and it is not a pretty picture. The backdoor web shell is verifiably present on the networks of thousands of U.S. organizations, including banks, credit unions, non-profits, telecommunications providers, public utilities and police, fire and rescue units. "It's police departments, hospitals, tons of city and state governments and credit unions," said one source who's working closely with federal officials on the matter. "Just about everyone who's running self-hosted Outlook Web Access and wasn't patched as of a few days ago got hit with a zero-day attack." Another government cybersecurity expert who participated in a recent call with multiple stakeholders impacted by this hacking spree worries the cleanup effort required is going to be Herculean. "On the call, many questions were from school districts or local governments that all need help," the source said, speaking on condition they were not identified by name. "If these numbers are in the tens of thousands, how does incident response get done? There are just not enough incident response teams out there to do that quickly." When it released patches for the four Exchange Server flaws on Tuesday, Microsoft emphasized that the vulnerability did not affect customers running its Exchange Online service (Microsoft's cloud-hosted email for businesses). But sources say the vast majority of the organizations victimized so far are running some form of Internet-facing Microsoft Outlook Web Access (OWA) email systems in tandem with Exchange servers internally. "It's a question worth asking, what's Microsoft's recommendation going to be?," the government cybersecurity expert said. "They'll say 'Patch, but it's better to go to the cloud.' But how are they securing their non-cloud products? Letting them wither on the vine." The government cybersecurity expert said this most recent round of attacks is uncharacteristic of the kinds of nation-state level hacking typically attributed to China, which tends to be fairly focused on compromising specific strategic targets. "Its reckless," the source said. "It seems out of character for Chinese state actors to be this indiscriminate." Microsoft has said the incursions by Hafnium on vulnerable Exchange servers are in no way connected to the separate SolarWinds-related attacks, in which a suspected Russian intelligence group installed backdoors in network management software used by more than 18,000 organizations. "We continue to see no evidence that the actor behind SolarWinds discovered or exploited any vulnerability in Microsoft products and services," the company said. Nevertheless, the events of the past few days may well end up far eclipsing the damage done by the SolarWinds intruders. This is a fast-moving story, and likely will be updated multiple times throughout the day. Stay tuned. Update, 8:27 p.m. ET: Wired cybersecurity reporter Andy Greenberg has confirmed hearing the same number of victim numbers cited in this report: "It's massive. Absolutely massive," one former national security official with knowledge of the investigation told WIRED. "We're talking thousands of servers compromised per hour, globally." Read Greenberg's account here. Also, the first and former director of CISA, Chris Krebs (no relation) seems to be suggesting on Twitter that the victim numbers cited here are conservative (or just outdated already): [chriskrebstweet2] Update 8:49 p.m. ET: Included a link to one of the more recommended tools for finding systems vulnerable to this attack. Update, 10:17 p.m. ET: Added mention from Reuters story, which said White House officials are concerned about "a large number of victims." Update, March 6, 10:56 a.m. ET: CISA's Twitter account says the agency "is aware of widespread domestic and international exploitation of Microsoft Exchange Server vulnerabilities and urges scanning Exchange Server logs with Microsoft's detection tool to help determine compromise." [cisatweet] A tweet today from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [93] Tags: Andy Greenberg, Chris Krebs, Hafnium, Jen Psaki, Microsoft Exchange server flaws, Steven Adair, Volexity, wired This entry was posted on Friday, March 5th, 2021 at 4:07 pm and is filed under Latest Warnings, The Coming Storm, Time to Patch. You can follow any comments to this entry through the RSS 2.0 feed. You can skip to the end and leave a comment. Pinging is currently not allowed. 77 comments 1. [b79d] Satobucks March 6, 2021 at 4:43 pm So are subscribers to Microsoft 365, formerly Office 365, affected if they use the Exchange SAS offering including OWA and/ or desktop Outlook (with or without custom domain)? Reply + [b79d] Robert S March 6, 2021 at 8:49 pm Answering to my own question. "The zero-days recently exploited include CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. Microsoft urges customers to update their on-premises systems with the patches "immediately" and says these flaws affect Microsoft Exchange Server versions 2013, 2016, and 2019. Exchange Online is not affected." Reply 2. [36e4] Robert Scroggins March 6, 2021 at 4:56 pm This is truly alarming! Thanks for your work, Brian. Regards, Reply 3. [30ca] jacksonn March 6, 2021 at 6:03 pm Good job sharing this with us. Now it's time to fix those vulnerabilities. Reply 4. [8c00] Brian Scott March 6, 2021 at 6:23 pm Once compromised, how do we evict the threat actor? I understand that installing the patches is recommended, however https://msrc-blog.microsoft.com/2021/03/05/ microsoft-exchange-server-vulnerabilities-mitigations-march-2021/ clearly states "This will not evict an adversary who has already compromised a server." Reply + [832a] name March 7, 2021 at 2:46 am the same thing you would do any other time your server is compromised? If you're not familiar with removing attackers from your network, your question is beyond the scope here. Reply 5. [8c00] Brian Scott March 6, 2021 at 6:32 pm How do we remove the threat actor after patches are installed? https://msrc-blog.microsoft.com/2021/03/05/ microsoft-exchange-server-vulnerabilities-mitigations-march-2021/ Clearly states, "This will not evict an adversary who has already compromised a server." Reply 6. [a8c9] arnim March 6, 2021 at 6:32 pm Important question: Is that really only Hafnium or also ransomware gangs which will soon start their usual business model? Why would Hafnium exploit the same server multiple times: https:/ /twitter.com/GossiTheDog/status/1368247470761852933 Sightings of mimikatz and cobalt strike: https://twitter.com/ _johnhammond/status/1368111199733374978 Reply 7. [dc40] Ham March 6, 2021 at 6:36 pm Microsoft is working with the Chicoms to destroy America. Big TECH is approved by Congress. Big Congress is OWNED> Too bad we see all your moves. Reply + [b462] Jeff Palmer March 6, 2021 at 9:46 pm I wish someone other than Koch funders would own Marsha Blackburn. That woman needs cybersecurity training. Reply o [8777] Scott March 6, 2021 at 10:56 pm No one of any reputation would support guns for hire like that. Training money would be wasted. Mercenary talking heads will say whatever you pay them to say. Reply 8. [5a6f] Cheese March 6, 2021 at 6:52 pm Yes Ham, my Q-brother! Big Dairy is also working to put us tasty sandwich items together on a toasted grain with EVIL CONDIMENTS. Big Mustard is surely in on the deal, to profit from us! IT'S CRAZY Reply + [bc70] sammich March 6, 2021 at 11:43 pm ROFL ... Reply 9. [ce04] Lindy March 6, 2021 at 8:59 pm Can someone explain why: "Its reckless," the source said. "It seems out of character for Chinese state actors to be this indiscriminate." ...There are no consequences for hackers in China or Russia or ( you name a country which doesn't respect laws and ethics.) Their governments would probably give them a bonus. Reply + [0503] timeless March 7, 2021 at 3:12 am Generally they perform targeted high value attacks. While they do that, they can claim it's a fair spy-v-spy thing. Attacking random civilians is the equivalent of an army switching from attacking military leaders to attacking random civilians, it's considered a war crime and would generally result in an escalation. While one plays spy-v-spy, the consequences are generally just to other spies. Reply o [392e] gordon March 7, 2021 at 3:01 pm There's no evidence (from any organization you can trust) it was a Chinese state actor. By this time, it should be clear that attribution is a failed endeavor - many cyber state actors can spoof anything. This was publicized by Taiwanese cyber sleuths in December 2020. This was another Microsoft failure. They happen. Reply 10. [bba0] Albert Maurice March 6, 2021 at 11:58 pm Peak navel gazing, American-style: "Volexity President Steven Adair said the company first saw attackers quietly exploiting the Exchange bugs on Jan. 6, 2021, a day when most of the world was glued to television coverage of the riot at the U.S. Capitol". Reply + [4159] Not Einstain March 7, 2021 at 1:09 pm "Volexity President Steven Adair said the company first saw attackers quietly exploiting the Exchange bugs on Jan. 6, 2021," What did Mr. Adair DO about it though? Why is it now two months later and the world is in rubble on the ground? These are question about which we must think. If Mr Adair told Microsoft and Microsoft just sat back and let this happen, then to Microsoft we must turn for funding to fix issue. If Mr Adair did not, then must he pay? Reply 11. [0728] Glen Ashcroft March 7, 2021 at 7:29 am I have as a best practice used ip address and domain restrictions in iis to lockdown the ecp folder to internal ips only on servers that publish on the internet, does this prevent the vulnerability? Reply + [2bee] Max March 7, 2021 at 4:59 pm Not at all. You also need to block /owa and /oab at the very least. Reply 12. [07e4] NEAred March 7, 2021 at 9:29 am 2 things; I wonder when the MS Cloud/Azure is being breached big time ... what is your opinion - never, soon or already? I wonder when organisations learn not to: ... standardize and uniform their infrastructure, ... stop listening to big-tech and "how great they are" ... stop spending money for non-working pain relief and start, ... transforming their infrastructure ... dump VPN, x.509, PIM/PAM, IAM, DLP, CASB etc. and other compromizable technologies and start implementing Sw. Def. Perimeter on layer 7, with SASE and Zero-Trust eXtended capabilities - and trunk all traffic through something like ZafePass - a solution connecting users with resources, services and applications - and the best part .... its designed with security first principles - you don't need to add anything - just click and work. Easy and convenient. - wonder when they to transform Reply + [4159] Not Einstein March 7, 2021 at 1:11 pm This an advert then? Reply 13. [08d5] Bill S March 7, 2021 at 1:25 pm When you design in backdoors for the alphabet organizations this is what happens when someone else finds the backdoor. More reasons for open source. Reply 14. [bcca] Cog March 7, 2021 at 4:46 pm When are there going to be any kind of consequences for this or the solar winds hack? Government and private sector consequences. Right now it seems as if there are none. Reply - Older Comments Leave a comment Click here to cancel reply. Name (required)[ ] Email (required)[ ] Website[ ] Comment [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [Submit Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] Advertisement [46] * [ ] [search_mag] [97] * Mailing List Subscribe here * Recent Posts + At Least 30,000 U.S. Organizations Newly Hacked Via Holes in Microsoft's Email Software + Three Top Russian Cybercrime Forums Hacked + Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder Emails + Payroll/HR Giant PrismHR Hit by Ransomware? + Is Your Browser Extension a Botnet Backdoor? * * All About Skimmers All About Skimmers Click image for my skimmer series. * Donate to Krebs On Security * Spam Nation Spam Nation A New York Times Bestseller! * * The Value of a Hacked PC valuehackedpc Badguy uses for your PC * Tools for a Safer PC Tools for a Safer PC Tools for a Safer PC * The Pharma Wars The Pharma Wars Spammers Duke it Out * Badguy Uses for Your Email Badguy Uses for Your Email Your email account may be worth far more than you imagine. * eBanking Best Practices eBanking Best Practices eBanking Best Practices for Businesses * Most Popular Posts + Sextortion Scam Uses Recipient's Hacked Passwords (1076) + Online Cheating Site AshleyMadison Hacked (798) + Sources: Target Investigating Data Breach (620) + Trump Fires Security Chief Christopher Krebs (534) + Cards Stolen in Target Breach Flood Underground Markets (445) + Reports: Liberty Reserve Founder Arrested, Site Shuttered (416) + Was the Ashley Madison Database Leaked? (376) + DDoS-Guard To Forfeit Internet Space Occupied by Parler (374) + True Goodbye: 'Using TrueCrypt Is Not Secure' (363) + Who Hacked Ashley Madison? (361) * Category: Web Fraud 2.0 Criminnovations Innovations from the Underground * [shreddedID-copy-285x189] ID Protection Services Examined * Is Antivirus Dead? Is Antivirus Dead? The reasons for its decline * The Growing Tax Fraud Menace The Growing Tax Fraud Menace File 'em Before the Bad Guys Can * Inside a Carding Shop Inside a Carding Shop A crash course in carding. * Beware Social Security Fraud Beware Social Security Fraud Sign up, or Be Signed Up! * How Was Your Card Stolen? How Was Your Card Stolen? Finding out is not so easy. * Krebs's 3 Rules... Krebs's 3 Rules... ...For Online Safety. --------------------------------------------------------------------- (c) 2021 Krebs on Security. Powered by WordPress. Privacy Policy