Microsoft has published multiple zero-day vulnerabilities used to attack on-premises versions of Microsoft Exchange Server that can be used in targeted attacks.
Microsoft Threat Intelligence Center stated that this campaign may be related to the technical tactics and procedures used by the group called HAFNIUM, which is considered to be supported by China.
In the observed attacks, it was stated that the attackers used these security vulnerabilities to access Exchange servers and used them to install additional malware to provide long-term, targeted access in their target environments.
Multiple security updates for exploited vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065) were released this week. It is recommended that the Exchange servers used be updated urgently.
In addition, the following links / addresses can be followed for updates:
Reported IoCs
-
Webshell Hashes
File Paths
Webshell File Names
Resources
+90 216 504 53 32
Aydınevler Mahallesi,İsmet İnönü Cadddesi,Küçükyalı Ofis Park A Blok,No:20/1 Maltepe İstanbul
+90 312 235 44 51
You can register to our newsletter on the home page to be instantly informed about security vulnerabilities.