Microsoft Reports 'DearCry' Ransomware Targeting Exchange Servers
Friday, March 12, 2021
Attackers have begun to deploy ransomware on Microsoft Exchange Servers compromised by the ProxyLogon exploits.
The idea of ransomware taking advantage of compromised Exchange servers has been a concern since attack activity ramped up following Microsoft's patch release. Ilia Kolochenko, founder and CEO of ImmuniWeb, says modern criminals are quick to launch large exploitation campaigns for all major vulnerabilities in a sufficient number of production systems.
"Some cybergangs gather terabytes of OSINT intelligence about Internet software, and once there is a zero-day, they sell compiled lists of IP addresses or URLs known to run the vulnerable software to other gangs," he explains.
This boosts the speed and efficient of exploitation, he continues. Combined with ransomware, these attack campaigns bring "huge and easy profits" to adversaries. Read Full Article
IT World Canada: Exchange Server vulnerabilities being exploited with ransomware, says Microsoft