New malware discovered to attack Microsoft Exchange server

NGUYỄN ĐĂNG |

Cybersecurity experts have just discovered a backdoor malware (also known as the backdoor) called GhostContainer, to attack the Microsoft Exchange server.

According to experts from Kaspersky's Global Research and Analysis Team (GReAT), this type of malware is built on open source tools. This is a sophisticated, undetectable type of malware.

The GReAT team discovered this malware in the incident response process at government systems using Microsoft Exchange (the email service commonly used for businesses and educational institutions).

GhostContainer is said to be part of an sophisticated and prolonged cyberattack (APT) campaign, targeting key organizations in the Asia region, including major technology companies.

This is a multi-functional malware that can be custom-generated by remotely downloading other modules. This malware takes advantage of many open source projects and is sophisticatedly customized to avoid detection.

Once GhostContainer is successfully installed into the system, hackers can easily completely control the Exchange server, thereby being able to commit a series of dangerous acts that users do not know about.

This malware is sophisticatedly disguised under the cover of a valid component of the server and uses many evasive monitoring techniques to avoid detection by virus programs and bypass the security monitoring system.

In addition, this malware can act as an intermediary server or a tunnel, creating loopholes for attackers to break into internal systems or steal important information.

Our in-depth analysis shows that the culprit behind the attack is very proficient in penetrating the Microsoft Exchange server system, said Sergey Lozhkin, head of GReAT Asia - Pacific and Middle East - Africa at Kaspersky. We will continue to monitor the group's activities as well as the range and level of danger of the attacks, to better understand the overall picture of the threat.

To avoid becoming victims of targeted attacks from well-known or undetected cybercriminal groups, cybersecurity experts Kaspersky recommend that businesses apply the following measures:

- Equip security operations teams (SOCs) with access to information sources about the latest threat.

- Improve the skills of the cybersecurity team, helping them prepare to deal with new threats with online training programs, designed by leading experts.

- Applying incident detection and handling solutions right from the terminal device, such as EDR to help detect, investigate and respond promptly to signs of attack.

- Combining additional security solutions at the enterprise network level, helping to detect complicated attacks that are quietly taking place in the system early.

- Since many targeted attacks often start with fraudulent emails or forms of psychological deception, it is necessary to organize training courses to raise employees' security awareness.

NGUYỄN ĐĂNG
TIN LIÊN QUAN

Warning about new malware targeting cryptocurrency wallets and online banking

|

A new variation of Coyote malware is taking advantage of legal features in Windows to steal users' bank information and cryptocurrency wallets.

New malware targets users on App Store and Google Play

|

Experts have just discovered a new type of malware called SparkKitty, designed to attack smartphones using iOS and Android operating systems.

Overview of the alternative route to Sa Pa after the BOT station collapsed

|

Lao Cai - Because the landslide at Sa Pa BOT station has not been repaired, vehicles will have to go through National Highway 4D.

The beautiful, talented sister of Hoa Minzy and Phuong My Chi

|

Hoa Minzy and Phuong My Chi both have beautiful and talented sisters.

Warning about new malware targeting cryptocurrency wallets and online banking

Cát Tiên (THEO indianexpress) |

A new variation of Coyote malware is taking advantage of legal features in Windows to steal users' bank information and cryptocurrency wallets.

Cảnh báo người dân tránh bẫy cài đặt mã độc rồi tưởng ứng dụng VNeID

Việt Dũng |

Bộ Công an cảnh báo, tội phạm lợi dụng việc sắp xếp các đơn vị hành chính ở địa phương, để mạo danh cơ quan quản lý nhà nước lừa đảo, cài mã độc.

New malware targets users on App Store and Google Play

NGUYỄN ĐĂNG |

Experts have just discovered a new type of malware called SparkKitty, designed to attack smartphones using iOS and Android operating systems.