• Unpatched Microsoft Exchange under Hive Ransomware Attack

    Home » Forums » Cyber Security Information and Advisories » Cyber Security for Business users » Unpatched Microsoft Exchange under Hive Ransomware Attack

    • This topic has 3 replies, 3 voices, and was last updated 3 years ago.
    Author
    Topic
    #2441150

    Hive Ransomware Analysis

    During a recent engagement with a customer, the Varonis Forensics Team investigated a ransomware incident. Multiple devices and file servers were compromised and encrypted by a malicious threat group known as Hive.

    First observed in June 2021, Hive is an affiliate-based ransomware variant used by cybercriminals to conduct ransomware attacks against healthcare facilities, nonprofits, retailers, energy providers, and other sectors worldwide. Hive is built for distribution in a Ransomware-as-a-service model that enables affiliates to utilize it as desired…

    The Forensics team observed that the actor managed to achieve its malicious goals and encrypt the environment in less than 72 hours from the initial compromise.

    First, the attacker exploited multiple Exchange security vulnerabilities, referred to as ProxyShell. Next, the attack placed a malicious backdoor script, referred to as webshell, in a publicly accessible directory on the Exchange server. These web scripts could then execute malicious PowerShell code over the compromised server with SYSTEM privileges..

    [Moderator edit] changed title to add “unpatched”

    Viewing 2 reply threads
    Author
    Replies
    • #2441219

      Microsoft released patches for those three vulnerabilities in April and May 2021

      malicious activities can be prevented by having … patches for known vulnerabilities in place.

    • #2441222

      Easy fix. Patch.

    • #2441223

      Actually the headline needs changing:

      Exchange servers that haven’t been properly maintained hit with attacks targeting unpatched Exchange servers.

    Viewing 2 reply threads
    Reply To: Unpatched Microsoft Exchange under Hive Ransomware Attack

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: