Technology

Hackers keep attacking Microsoft Exchange servers since 2021

Security researchers have discovered that unknown hackers have been targeting Microsoft Exchange servers at government and military institutions with new malware since early 2021. Currently, many networks are said to have infiltrated unnoticed. This is mainly because, despite the vulnerabilities that became known in 2021, many Exchange servers are still not updated and therefore secured.

This is according to a report by Kaspersky security researchers. Not much is known about the attackers. This is probably mainly due to the fact that they have been able to operate undetected for so long. It uses malware that Kaspersky called SessionManager. This is a malicious native code module for the Internet Information Services (IIS) for Exchange Server.

Unobtrusive entrances

“The SessionManager backdoor provides attackers with persistent, update-resistant, and rather unobtrusive access to a target company’s IT infrastructure,” explains Kaspersky in a blog published today. “Once inside the victim’s system, cybercriminals can gain backdoor access to corporate email, update further malicious access by installing other types of malware, or covertly manage compromised servers that can be used as malicious infrastructure.” So far we have mainly read about those affected in Europe, Asia, Africa, and the Middle East.

After the malware is installed, credentials and other information from the victims’ network and the infected devices are collected and sent to the hackers. “Exploiting vulnerabilities in Exchange servers has been a popular target for cybercriminals to gain access to targeted infrastructure since Q1 2021. The newly discovered SessionManager was barely detected in a year and is still being used in the wild,” explains Pierre out. Delcher, a senior security researcher at Kaspersky.

Connections to the Gelsemium hacking group

Due to the similar victimology, Kaspersky’s security researchers believe the new attacks were launched by a group called Gelsemium as part of a global espionage operation. This hacker group has been active since at least 2014. 

Recent Posts

Multikernel Linux: Multiple Linux systems without a VM on one device

Multikernel Technologies has a public version of its multikernel Linux for the first time with…

6 hours ago

Memory crisis makes you creative: New MSI laptop with DDR4 or DDR5

The world's PC manufacturers are in a bind when it comes to memory. DDR4 RAM…

6 hours ago

Gamescom 2026: Series of thefts hit small indie developers hard

How safe are the protected halls of Gamescom 2026 really? After the night-time theft of…

7 hours ago

GrapheneOS: No secure Android for the Pixel 11 because Google is sloppy?

Google has apparently made changes to the security features of the Pixel 11 series, which…

7 hours ago

The Smart Girl’s Guide to Staying Safe Online While Shopping

Bagging a bargain online has never been easier - or riskier. Between dodgy "influencer" deals…

8 hours ago

Google against website operators: AI overview in search even larger

Google is expanding its AI overviews and is now displaying even more information and details…

8 hours ago