Microsoft Says Chinese Hackers Responsible for Exchange Attacks

Microsoft Exchange Attacks Featured

Microsoft had a warning for its customers on Tuesday, and it’s boldly calling out the bad actors. According to Microsoft, Chinese hackers are behind Exchange attacks. The company claims American businesses were targeted by exploits of a flaw in the email product.

Chinese Attackers Exploit Microsoft Exchange

Microsoft called attention to four zero-day vulnerabilities that were recently discovered. The company connected the Exchange attacks to patches and a list of compromise indicators.

Researchers with the company have labeled the hacking group as “HAFNIUM.” They explained the group is a “highly skilled and sophisticated actor” with a focus on espionage through data theft. HAFNIUM has been known to pursue several U.S. entities, including “infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks and NGOs,” according to the researchers.

Microsoft Exchange Attacks Laptop

The Exchange attacks have led to data exfiltration from email accounts. The hackers gain entry to an Exchange server by leveraging zero days. They often used a web shell and remotely hijack the servers. This allows them to steal data from an associated network. Microsoft said these attacks were launched from U.S.-based private servers.

Tom Burt, Microsoft corporate vice president of customer security, urged Exchange customers to quickly update the security flaws. “Even though we’ve worked quickly to deploy an update for the HAFNIUM exploits, we know that many nation-state actors and criminal groups will move quickly to take advantage of any unpatched systems. Promptly applying today’s patches is the best protection against this attack,” he said.

Researchers at two separate security firms, Volexity and Dubex, brought the Exchange attacks to the attention of Microsoft. The Volexity researchers found evidence of the attacks on January 6.

Microsoft Exchange Attacks Data

In a blog post, the researchers said, “Through its analysis of system memory, Volexity determined the attacker was exploiting a zero-day server-side request forgery (SSRF) vulnerability in Microsoft Exchange (CVE-2021-26855). The attacker was using the vulnerability to steal the full contents of several user mailboxes. This vulnerability is remotely exploitable and does not require authentication of any kind, nor does it require any special knowledge or access to a target environment. The attacker only needs to know the server running Exchange and what account from which they want to extract e-mail.”

Not Associated with “SolarWinds”

Microsoft has been getting it from all angles lately. They’re also entangled in the SolarWinds mess. But according to the company, the Exchange attack is not connected to Solar Winds.

It has not been announced how many businesses have been affected by the Exchange attacks. It’s also believed that HAFNIUM may not be acting alone and that there may be more involved. Federal authorities have been brought up to speed on the Exchange attacks.

Read the warning Microsoft issued last fall regarding a spike in cyberattacks due to the pandemic.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

Octopuses possess roughly 500 million neurons distributed across their body, with two-thirds located in their arms rather than their central brain, meaning each arm can taste, problem-solve, and react to stimuli independently of whatever the octopus is otherwise paying attention to.
The Roman aqueduct at Segovia, built around the first century AD without mortar, still carried water into the 1970s, its 167 granite arches held together by nothing but the precise weight distribution of stones cut to fit each other within fractions of a millimeter.
When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.