Published: in News

HAFNIUM targeting Exchange Servers with 0-day exploits

By Sam Sheridan - 3rd March, 2021

Microsoft has detected multiple 0-day exploits being used to attack on-premises versions of Microsoft Exchange Server in limited and targeted attacks. In the attacks observed, the threat actor used these vulnerabilities to access on-premises Exchange servers which enabled access to email accounts, and allowed installation of additional malware to facilitate long-term access to victim environments. Microsoft Threat Intelligence Center (MSTIC) attributes this campaign with high confidence to HAFNIUM, a group assessed to be state-sponsored and operating out of China, based on observed victimology, tactics and procedures.

After exploiting these vulnerabilities to gain initial access, HAFNIUM operators deployed web shells on the compromised server. Web shells potentially allow attackers to steal data and perform additional malicious actions that lead to further compromise.

Microsoft has released a set of out of band security updates for vulnerabilities for the following versions of Exchange Server

  • Exchange Server 2013
  • Exchange Server 2016
  • Exchange Server 2019

Security updates are also available for Microsoft Exchange 2010 SP3, if you haven't upgraded Exchange 2010 to SP3 then this will need to be done before you can apply the patch.

Microsoft has posted a blog post on these new security updates.

Source:

Microsoft - March 2021: HAFINUM targeting exchange servers

 

Tags:

exploit microsoft microsoft exchange

Got Questions?

Find quick answers to common IT support questions

How quickly can you respond to IT issues?

While many companies claim a 15-minute response, we guarantee a one-hour response time for urgent issues. This realistic timeframe allows our expert team to mobilise properly and arrive fully prepared to diagnose and resolve the problem efficiently - ensuring quality support rather than a rushed service.

How long has Sheridan Computers been established?

We've proudly been established for over 15 years. Our enduring presence in the IT industry is a testament to our commitment to quality, innovation, and reliable service. We’re here for the long haul, continuously evolving to meet the needs of our customers today - and in the future.

IT Emergency?

24/7 emergency IT support available for existing clients

Help & Support
Standard Support Hours
Monday - Friday 8:00 - 18:00
Saturday Closed
Sunday Closed
Other Ways to Reach Us
24/7 Emergency Support

Critical issues? Our emergency team is available 24/7 for existing clients.

Emergency Support Line