Microsoft Exchange servers are under attack once again

- Advertisement -

“BlackKingdom” is the newest discovered campaign that is hacking into the Microsoft Exchange server and is leveraging the ProxyLogon vulnerabilities to deploy ransomware.

Marcus Hutchins from MalwareTechBlog Tweeted saying “Someone just ran this script on all vulnerable Exchange servers via ProxyLogon vulnerability. It claims to be BlackKingdom “Ransomware”, but it doesn’t appear to encrypt files, just drops a ransom note to every directory. According to my honeypot backlog, the same attacker ran the following script a few days prior, but it failed.”

The web attackers tried to push ransomware to Hutchins’s Honeypots but they did not become encrypted and the attempt failed. Although this attack was did not go through it doesn’t mean that the hackers have not succeeded in encrypting other software. The BlackKingdom has been able to encrypt other devices from about mid- March. So far BlackKingdom has infected victims in the US, Canada, Austria, Switzerland, Russia, France, Israel, the UK, Italy, Germany, Greece, Australia and Croatia.

When successfully deployed, the ransomware encrypts files using random extensions and then leaves a ransom note named decrypt_file.TxT. However, in his research, Hutchins found a different ransom note named ReadMe.txt which used text that is slightly different. Both ransom notes request that victims pay $10,000 in bitcoin to unencrypt their servers.

This isn’t the first time that a ransomware known as BlackKingdom has been observed in the wild. Back in June of last year, another ransomware by the same name was used to compromise corporate networks by exploiting vulnerabilities in Pulse VPN. Although it has yet to be confirmed, both versions of the BlackKingdom ransomware were written in Python.

Another ransomware known as DearCry was also used to launch attacks against Microsoft Exchange servers by exploiting the ProxyLogon vulnerabilities earlier this month.

Hot this week

Has India Quietly Achieved Maritime Deterrence Without Firing a Shot?

(Commonwealth_India) Prime Minister Narendra Modi marked this year’s Diwali...

Which Rare Deep-Sea Creatures Have Scientists Just Uncovered in Western Australia?

An Australian scientific expedition has revealed an impressive collection...

Bollywood’s best-kept secret is out: Baby Dua steals the show in Diwali festivities!

Mumbai (Commonwealth Union)_ Deepika Padukone and Ranveer Singh, Bollywood's...

White House Diwali turns diplomatic: Trump hails Modi, signals major India moves at Diwali event!

India (Commonwealth Union)_ US President Donald Trump hosted Diwali...

Feast of Pope St. John Paul II

Karol Wojtyła was born in 1920 in Wadowice, Poland....
- Advertisement -

Related Articles

- Advertisement -sitaramatravels.comsitaramatravels.com

Popular Categories

Commonwealth Union
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.