MS Exchange Server-Schwachstellen werden für gezielte Angriffe mit Keyloggern ausgenutzt

Teilen:

An unknown threat actor is exploiting known security flaws in Microsoft Exchange Server to deploy a keylogger malware in attacks targeting entities in Africa and the Middle East.

Russian cybersecurity firm Positive Technologies said it identified over 30 victims spanning government agencies, banks, IT companies, and educational institutions. The first-ever compromise dates back to 2021.

“This keylogger was collecting account credentials into a file accessible via a special path from the internet,” the company sagte in a report published last week.

Countries targeted by the intrusion set include Russia, the U.A.E., Kuwait, Oman, Niger, Nigeria, Ethiopia, Mauritius, Jordan, and Lebanon.

The attack chains commence with the exploitation of ProxyShell flaws (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) that were originally patched by Microsoft in May 2021.

Successful exploitation of the vulnerabilities could allow an attacker to bypass authentication, elevate their privileges, and carry out unauthenticated, remote code execution. The exploitation chain was discovered and published by Orange Tsai from the DEVCORE Research Team.

MS Exchange Server Flaws

The ProxyShell exploitation is followed by the threat actors adding the keylogger to the server main page (“logon.aspx”), in addition to injecting code responsible for capturing the credentials to a file accessible from the internet upon clicking the sign in button.

Positive Technologies said it cannot attribute the attacks to a known threat actor or group at this stage without additional information.

Besides updating their Microsoft Exchange Server instances to the latest version, organizations are urged to look for potential signs of compromise in the Exchange Server’s main page, including the clkLgn() function where the keylogger is inserted.

“If your server has been compromised, identify the account data that has been stolen and delete the file where this data is stored by hackers,” the company said. “You can find the path to this file in the logon.aspx file.”

Ravie Lakshmanan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:57 am, Juni 27, 2025
Wetter-Symbol 13°C
L: 12° | H: 14°
overcast clouds
Luftfeuchtigkeit: 85 %
Druck: 1020 mb
Wind: 4 mph S
Windböe: 6 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:45 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 14°°C 1 mm 100% 13 mph 86 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 11 mph 91 % 1025 mb 0 mm/h
So. Juni 29 10:00 pm
Wetter-Symbol
18° | 32°°C 0 mm 0% 6 mph 78 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
22° | 36°°C 0.2 mm 20% 8 mph 65 % 1021 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
22° | 31°°C 0 mm 0% 9 mph 70 % 1015 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
14° | 15°°C 1 mm 100% 7 mph 86 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
18° | 21°°C 0 mm 0% 11 mph 69 % 1020 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 12 mph 54 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 13 mph 39 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 13 mph 38 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 10 mph 63 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 9 mph 83 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 9 mph 91 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,924.47
-0.38%
Ethereum(ETH)
€2,090.88
-1.69%
Fesseln(USDT)
€0.86
-0.02%
XRP(XRP)
€1.80
-3.96%
Solana(SOL)
€120.98
-3.22%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.138889
-2.17%
Shiba Inu(SHIB)
€0.000009
-3.05%
Pepe(PEPE)
€0.000008
-3.46%
Nach oben scrollen