Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

The new visa rule in the US requires from applicants to set privacy in social media for the public

June 24, 2025

Hackers focus on over 70 Microsoft Exchange servers to steal credentials via Keyloggers

June 24, 2025

Researchers find a way to close Cryptominer companies using bad stocks and Xmrogue

June 24, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Hackers focus on over 70 Microsoft Exchange servers to steal credentials via Keyloggers
Global Security

Hackers focus on over 70 Microsoft Exchange servers to steal credentials via Keyloggers

AdminBy AdminJune 24, 2025No Comments3 Mins Read
Microsoft Exchange Servers
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


June 24, 2025Red LakshmananVulnerability / malicious software

Microsoft Exchange servers

Unknown threats were observed on publicly exposed Microsoft Exchange servers to introduce malicious code into the entry pages that collect their powers.

Positive technology in a new analysis published last week, – Note He identified two different types of Keylogger code written on JavaScript on the Outlook login page –

  • The ones that store the collected data to the local file available over the Internet
  • Those who immediately sends the collected data to the external server
Cybersecurity

Russian cybersecurity supplier said the attacks were aimed at 65 victims in 26 countries, and is reported Continued company This was first recorded in May 2024 as a target to Africa and the Middle East.

At the time, the company said it had found at least 30 victims covering state bodies, banks, IT companies and educational institutions, which testifies to the first compromise that begins by 2021.

The attack networks provide for the operation of known deficiencies on the Microsoft Exchange server (eg Proxyshell) to insert the Keylogger code into the entry page. It is now unknown who is behind these attacks.

Some armed vulnerabilities are below – below –

  • Cve-2014-4078-in the IIS security feature
  • Cve-2020-0796-Windows SMBV3 Customer/Server Remote Code Vulneration
  • CVE-2021-26855, Cve-2021-26857, Cve-2021-26858 and Cve-2011-27065-Recovery remote code Microsoft Exchange Code (Proxylogon)
  • CVE-2021-31206-Benching Remote Microsoft Exchange Server Code Code Code
  • Cve-2021-31207, Cve-2021-34473, Cve-2021-34523-Up Breaking Microsoft Exchange Server Security (Proxyshell)

‘JavaScript reads and processes data from the authentication form and then sends it through Request Xhr On a specific page on the compromised Exchange server, ” – said Klimentiy Galkin and Maxim Suslov security researchers.

“The source code of the target page contains the handler feature that reads the incoming request and records the data to the file on the server.”

The file containing stolen data is available from the external network. It has been found that selected options with the possibility of a local keyboard are also collected by user files, user strings and a temporary brand.

One of the advantages of this approach is that the chances of detecting have nothing because there is no outgoing traffic to transmit information.

The second option, revealed by positive technologies, on the other hand, uses a bot telegram as an Experience point through XHR to receive requests with coded entrance and password stored in the Apikey and Authtoken headlines respectively.

Cybersecurity

The second method involves the use of domain names (DNS) tunnel Combined with the HTTPS message to send user credentials and penetrate the organization’s defense.

Twenty -two violated servers were found in state organizations, after which infections in IT, industrial and logistics companies. Vietnam, Russia, Taiwan, China, Pakistan, Lebanon, Australia, Zambia, the Netherlands and Turkey are among the top 10 goals.

“A large number of Microsoft Exchange servers available on the Internet remain vulnerable to old vulnerabilities,” the researchers said. “Having built the malicious code into the legal authentication pages, the attackers may go unnoticed over a long period, capturing users’ accounts in the open text.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

The new visa rule in the US requires from applicants to set privacy in social media for the public

June 24, 2025

Researchers find a way to close Cryptominer companies using bad stocks and Xmrogue

June 24, 2025

APT28 uses signal chat to expand malicious Beardhell ​​and Testament software in Ukraine

June 24, 2025

Talk CTEM we all need

June 24, 2025

Hackers operate incorrectly configured API Docker to hand over cryptocurrency via Tor Network

June 24, 2025

US House forbids WhatsApp on official security and protection devices

June 24, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

The new visa rule in the US requires from applicants to set privacy in social media for the public

June 24, 2025

Hackers focus on over 70 Microsoft Exchange servers to steal credentials via Keyloggers

June 24, 2025

Researchers find a way to close Cryptominer companies using bad stocks and Xmrogue

June 24, 2025

APT28 uses signal chat to expand malicious Beardhell ​​and Testament software in Ukraine

June 24, 2025

Talk CTEM we all need

June 24, 2025

Hackers operate incorrectly configured API Docker to hand over cryptocurrency via Tor Network

June 24, 2025

US House forbids WhatsApp on official security and protection devices

June 24, 2025

Salt Typhoon associated with China

June 24, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

The new visa rule in the US requires from applicants to set privacy in social media for the public

June 24, 2025

Hackers focus on over 70 Microsoft Exchange servers to steal credentials via Keyloggers

June 24, 2025

Researchers find a way to close Cryptominer companies using bad stocks and Xmrogue

June 24, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.