Technology

Microsoft Exchange Server is Targeted by Email Hijacking Attacks

Unpatched Microsoft Exchange servers are increasingly targeted by unknown hackers. A trick has spread that is not so easy for many users to grasp at first: the hackers use existing email conversations to fake legitimacy. That comes from a new report Security researchers from Intezer off (via bleeding computer The security researchers discovered that the so-called IcedID malware is currently spreading massively through an Exchange Server vulnerability. This malware is known as a modular banking Trojan that not only robs banking information but also installs so-called second-stage malware, such as loaders or ransomware. Infographic Often heard – never used: protective measures on the internet

conversation hijack attack

There is a very simple and annoying trick to access their victim system: the hackers give their victims the impression that they are receiving an email from their network. They do this through reply emails, or “turning on” an existing conversation. For example, these response chains share a link to the download of an alleged Word document or a download link for each file containing the IcedID malware. The hackers are specifically looking for Exchange servers that have not loaded the latest security updates and are therefore vulnerable.

The number of campaigns spreading malware in this way has increased significantly through the response chain tricks. The main method of a conversation hijacking attack is to take control of an email account that is involved in a discussion with the target person and then send a phishing message created to make them look like a continuation of the conversation. thread.

The target is almost exclusively companies. If the target receives a reply message with an attachment mentioned as relevant to the previous discussion, the chances of them suspecting fraud are minimized. Intezer explains that there is evidence that threat actors are targeting vulnerable Microsoft Exchange servers to steal credentials, as many of the compromised endpoints they found are publicly available and unpatched.

Recent Posts

Update chaos after patch day: WSUS server refuses synchronization

After Windows Patch Day in July 2026, reports of problems with the Windows Server Update…

1 day ago

PayPal Gets $53 Billion Takeover Offer from Stripe

The payment service provider PayPal is apparently facing a large-scale takeover. Two investors have submitted…

1 day ago

GTA 3 and Vice City run on in-game TV in San Andreas

A new mod for GTA San Andreas lets players play two older parts of the…

1 day ago

Emergency Alert: Robotaxis are helpless if passengers fall asleep

With the increasing spread of autonomous robotaxis, not only the technical capabilities of the vehicles…

1 day ago

UK to introduce mileage tax for electric cars in 2028

From 2028, electric car drivers in the UK will have to pay a distance-based levy.…

1 day ago

Galaxy Watch 9 & Ultra 2 Leak comes with smartwatches in official photos

Shortly before the next Unpacked event on July 22nd, official promo images of the new…

1 day ago