Microsoft Says Chinese Hackers Targeted US Groups via Its Exchange Server Software

Microsoft says Chinese hacking group that it calls Hafnium was able to trick Exchange servers into allowing it to gain access.

Advertisement
By Reuters | Updated: 3 March 2021 10:46 IST
Highlights
  • Group is based in China but operates from leased virtual private servers
  • The hackers' increasingly aggressive moves began to attract attention
  • Hackers who went after SolarWinds also breached Microsoft itself

Microsoft's near-ubiquitous suite of products has been under scrutiny since the hack of SolarWinds

A China-linked cyberespionage group has been remotely plundering email inboxes using freshly discovered flaws in Microsoft mail server software, the company and outside researchers said on Tuesday - an example of how commonly used programmes can be exploited to cast a wide net online.

In a blog post, Microsoft said the hacking campaign made use of four previously undetected vulnerabilities in different versions of the software and was the work of a group it dubs HAFNIUM, which it described as a state-sponsored entity operating out of China.

In a separate blog post, cybersecurity firm Volexity said that in January it had seen the hackers use one of the vulnerabilities to remotely steal "the full contents of several user mailboxes." All they needed to know were the details of Exchange server and of the account they wanted to pillage its emails, Volexity said.

Advertisement

The Chinese Embassy in Washington did not immediately return messages seeking comment. Beijing routinely denies carrying out cyberespionage despite a drumbeat of allegations from the United States and others.

Advertisement

Ahead of the Microsoft announcement, the hackers' increasingly aggressive moves began to attract attention from across the cyber-security community.

Mike McLellan, director of intelligence for Dell's Secureworks, said ahead of the Microsoft announcement that he had noticed a sudden spike in activity touching Exchange servers overnight on Sunday, with around 10 customers affected at his firm.

Advertisement

Microsoft's near-ubiquitous suite of products has been under scrutiny since the hack of SolarWinds, the Texas-based software firm that served as a springboard for several intrusions across government and the private sector. In other cases, hackers took advantage of the way customers had set up their Microsoft services to compromise their targets or dive further into affected networks.

Hackers who went after SolarWinds also breached Microsoft itself, accessing and downloading source code - including elements of Exchange, the company's email, and calendaring product.

Advertisement

McLellan said that for now, the hacking activity he had seen appeared focused on seeding malicious software and setting the stage for a potentially deeper intrusion rather than aggressively moving into networks right away.

"We haven't seen any follow-on activity yet," he said. "We're going to find a lot of companies affected but a smaller number of companies actually exploited."

Microsoft said targets included infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and non-governmental groups.

© Thomson Reuters 2021
 


Is Samsung Galaxy F62 the best phone under Rs. 25,000? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Microsoft, SolarWinds
Advertisement

Related Stories

Popular Mobile Brands
  1. These New AI Features Are Coming to Your Updated iPhone, iPad and Mac
  2. Samsung Galaxy Tab A11, Tab A11+ Design, Features Leaked Ahead of Launch
  3. iPhone 17 Pro Max Cosmic Orange Variant Out of Stock in the US, India: Report
  4. Amazon Sale 2025: Early Deals on Smartphones
  5. Google Pixel 10 Review: A Brilliant Phone We Wanted to Love
  6. iOS 26 Update Brings These New Features to AirPods Pro 3, Pro 2, AirPods 4
  7. Early Deals on PlayStation 5 and Accessories Revealed Ahead of Amazon Sale
  8. Check What's New for Your iPhone in Apple's Latest iOS 26 Update
  9. Oppo Find X9 Pro Chipset, AnTuTu and Geekbench Scores Revealed
  10. Google: India Leads Nano Banana Trend; Shares Tip to Start Next One
  1. Vivo V60e Price and Specifications Reportedly Surface Ahead of India Launch
  2. Sony Said to Be Planning State of Play Broadcast for Next Week
  3. France Could Block Crypto Firms With MiCA Licenses Due to Enforcement Gap Concerns
  4. Oppo Find X9 Pro With Dimensity 9500 SoC Scores 4 Million Points on AnTuTu; Spotted on Geekbench
  5. Xiaomi 17 Pro Design Render Gives Us a Good Look at Its Leica-Branded Rear Cameras, Secondary Display
  6. Clair Obscur: Expedition 33 Has Sold 4.4 Million Copies in Less Than Six Months of Launch
  7. Materialists Now Streaming on Netflix: What You Need to Know About Dakota Johnson’s Starrer Movie
  8. The Trial Season 2 OTT Release Date: When and Where to Watch Kajol’s Legal Drama Series Online
  9. Ghaati OTT Release Reportedly Revealed Online: When and Where to Watch Anushka Shetty-Starrer Movie Online?
  10. American Express Launches NFT Passport Stamps to Commemorate Travel Memories
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.