Exchange Exploit Attempts Surge Sixfold as Ransomware Lands

Stu Sjouwerman | Mar 15, 2021

Microsoft Exchange Hack KnowBe4 WebinarThe Phil Muncaster at Info Security Mag had it first: "The number of global exploit attempts targeting vulnerable Microsoft Exchange servers has risen sixfold over the past few days, as Microsoft warned of a new ransomware threat to compromised systems.

Check Point Research has been monitoring the situation since Microsoft released out-of-band patches for four zero-day bugs back on March 3.

Reports began emerging that a Chinese state-backed group dubbed Hafnium was behind attacks in the wild exploiting the flaws. Then global attacks ramped-up massively, with some estimates claiming 30,000 victims in the US and over 100,000 round the world.

ESET said this was the result of multiple other APT groups getting involved.

Having previously said on Friday that exploit attempts on Exchange servers were doubling every few hours, Check Point then noted in an update on Sunday that they had surged sixfold over the past 72 hours.

The US accounted for 21% of these, followed by the Netherlands (12%) and Turkey (12%), with government and military the hardest hit sector (27%) followed by manufacturing (22%) and software vendors (9%).

Also on Friday, Microsoft tweeted that it had detected a new ransomware family being deployed after initial compromise of unpatched Exchange servers.

“Microsoft protects against this threat known as Ransom:Win32/DoejoCrypt.A, and also as DearCry,” it said.

Mandiant vice-president of analysis, John Hultquist, warned that this could be the start of a flood of exploitation activity by ransomware threat actors."  The full article is here: https://www.infosecurity-magazine.com/news/exchange-exploit-attempts-sixfold/

We strongly recommend you take 25 minutes and watch this RUSH ON-DEMAND WEBINAR, 

Topics: Ransomware

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.