Chinese cyberespionage group hacks US organizations with Exc

Chinese cyberespionage group hacks US organizations with Exchange zero-day flaws


MaxKabakov / Getty Images
Microsoft has released emergency patches for four previously unknown vulnerabilities in Exchange Server that a cyberespionage group was exploiting to break into organizations. The flaws allow the extraction of mailbox contents and the installation of backdoors on vulnerable servers.
Microsoft attributes the attacks to a Chinese APT group dubbed Hafnium that has a history of exploiting vulnerabilities in internet-facing servers and targeting Office 365 users. The group has targeted entities in the US including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.
Authentication bypass
The attacks were initially spotted in January by researchers from security firm Volexity after observing unusual connections and data transfers to suspicious IP addresses from the Exchange servers of some of its customers. A subsequent investigation revealed suspicious POST requests to legitimate resources on the Exchange servers, leading the researchers to suspect they had been backdoored.

Related Keywords

China , Chinese , Sysinternals Psexec , Exchange Server , Database Availability Group , Microsoft , Active Directory , China Chopper , Unified Messaging , சீனா , சீன , பரிமாற்றம் சேவையகம் , தரவுத்தளம் கிடைக்கும் குழு , மைக்ரோசாஃப்ட் , செயலில் அடைவு , சீனா இடைநிலை , ஒருங்கிணைந்த செய்தி அனுப்புதல் ,

© 2025 Vimarsana