The US is showing serious concern over a cyberattack on Microsoft’s Exchange email software that the tech company has blamed on China. The attack affected thousands of on-premises email customers, small businesses, enterprises, and government organizations around the world.

On March 7th, the European Banking Authority (EBA) released an official statement saying it has removed all e-mail systems after their Microsoft Exchange Servers were hacked as part of the continuous attacks. EBA is part of the European System of Financial Guidance and it manages the stability organized performance of the EU banking sector.

The European Banking Authority (EBA) has been the subject of a cyber-attack against its Microsoft Exchange Servers, which is affecting many organizations worldwide. The Agency has swiftly launched a full investigation, in close cooperation with its ICT provider, a team of forensic experts, and other relevant entities.

Additionally, EBA initially stated that the hackers may have gotten to individual details kept on the e-mail servers. However, an upgrade released yesterday pointed out that no indications of information exfiltration have been discovered by forensic specialists.

At this stage, the EBA email infrastructure has been secured and our analyses suggest that no data extraction has been performed and we have no indication to think that the breach has gone beyond our email servers.

Who is Behind the Attacks?

The Microsoft Threat Intelligence Center (MSTIC) identified the new threat actor as “Hafnium” and they believe it operates from China. Hafnium has been attacking infectious disease researchers, law firms, universities, defense contractors, policy think tanks, and NGOs across the US aiming to exfiltrate sensitive information. The hackers access not only gained access to the victims’ emails but also to their entire networks using four distinct zero-day exploits.

According to Tom Burt, Corporate Vice President, Customer Security and Trust at Microsoft,

Historically, Hafnium primarily targets entities in the United States for the purpose of exfiltrating information from a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. While Hafnium is based in China, it conducts its operations primarily from leased virtual private servers (VPS) in the United States.

While conducting their research, MSTIC discovered that Hafnium would first gain access to an Exchange Server either with stolen passwords or by using the previously unknown vulnerabilities to pass for someone who should have access.

Heimdal Official Logo
Email is the most common attack vector used as an entry point into an organization’s systems.

Heimdal® Email Security

Is the next-level email protection solution which secures all your incoming and outgoing comunications.
  • Completely secure your infrastructure against email-delivered threats;
  • Deep content scanning for malicious attachments and links;
  • Block Phishing and man-in-the-email attacks;
  • Complete email-based reporting for compliance & auditing requirements;
Try it for FREE today 30-day Free Trial. Offer valid only for companies.

Initially, Microsoft believed the attacks are only connected to Hafnium, but in a recent blog update, the tech giant says several other threat actors exploit the recently patched Exchange flaws in similar campaigns.

Microsoft has updated their Microsoft Safety Scanner (MSERT) tool to detect web shells deployed in these attacks and a PowerShell script to search for indicators of compromise (IOC) in Exchange log files.

What’s more, following these attacks, CISA (Cybersecurity and Infrastructure Security Agency) has published a Remediating Microsoft Exchange Vulnerabilities guide and strongly urges all organizations to address the recent Microsoft Exchange Server product exploits as soon as possible.

Microsoft Warns Customers Against New China Cyberattack on Exchange Email

Leave a Reply

Your email address will not be published. Required fields are marked *