Microsoft Mail Exchange Server Flaw Exploited by at Least 10 Hacking Groups, Researchers Say

Microsoft’s patches do not remove any back door access that has already been left on the machines.

Advertisement
By Reuters | Updated: 11 March 2021 10:07 IST
Highlights
  • Microsoft declined comment on the pace of customers' updates
  • The hacking has appeared to be focused on cyber espionage
  • Experts are concerned about the prospect of ransom-seeking cybercriminals

Taiwan-based researchers reported to Microsoft on that they had found two new flaws which need patching

At least 10 different hacking groups are using recently discovered flaws in Microsoft's mail server software to break in to targets around the world, cybersecurity company ESET said in a blog post on Wednesday.

The breadth of the exploitation adds to the urgency of the warnings being issued by authorities in the United States and Europe about the weaknesses found in Microsoft's Exchange software.

Advertisement

The security holes in the widely used mail and calendaring solution leave the door open to industrial-scale cyber espionage, allowing malicious actors to steal emails virtually at will from vulnerable servers or move elsewhere in the network. Tens of thousands of organisations have already been compromised, Reuters reported last week, and new victims are being made public daily.

Earlier on Wednesday, for example, Norway's parliament announced data had been "extracted" in a breach linked to the Microsoft flaws. Germany's cybersecurity watchdog agency also said on Wednesday two federal authorities had been affected by the hack, although it declined to identify them.

Advertisement

While Microsoft has issued fixes, the sluggish pace of many customers' updates - which experts attribute in part to the complexity of Exchange's architecture - means the field remains at least partially open to hackers of all stripes. The patches do not remove any back door access that has already been left on the machines.

In addition, some of the back doors left on compromised machines have passwords that are easily guessed, so that newcomers can take them over.

Advertisement

Microsoft declined comment on the pace of customers' updates. In previous announcements pertaining to the flaws, the company has emphasized the importance of "patching all affected systems immediately."

Although the hacking has appeared to be focused on cyber espionage, experts are concerned about the prospect of ransom-seeking cybercriminals taking advantage of the flaws because it could lead to widespread disruption.

Advertisement

ESET's blog post said there were already signs of cybercriminal exploitation, with one group that specialises in stealing computer resources to mine cryptocurrency breaking in to previously vulnerable Exchange servers to spread its malicious software.

ESET named nine other espionage-focused groups it said were taking advantage of the flaws to break in to targeted networks - several of which other researchers have tied to China. Microsoft has blamed the hack on China. The Chinese government denies any role.

Intriguingly, several of the groups appeared to know about the vulnerability before it was announced by Microsoft on March 2.

Ben Read, a director with cybersecurity company FireEye, said he could not confirm the exact details in the ESET post but said his company had also seen "multiple likely-China groups" using the Microsoft flaws in different waves.

ESET researcher Matthieu Faou said in an email it was "very uncommon" for so many different cyber espionage groups to have access to the same information before it is made public.

He speculated that either the information "somehow leaked" ahead of the Microsoft announcement or it was found by a third party that supplies vulnerability information to cyber spies.

Taiwan-based researchers reported to Microsoft on January 5 that they had found two new flaws which need patching. Those two were among those that began being used by the attackers shortly before or after the friendly report.

They said were investigating whether there had been a theft or leak on their side, since exploitation was discovered in the wild the same week later. So far, the group called Devcore said, they had found no evidence.

Top-flight hackers are also commonly targeted by other hackers. Just this week, Microsoft patched one of the flaws used by suspected North Koreans in attempts to steal information from Western researchers.

But simultaneous discovery happens fairly often, in part because researchers use the same or similar tools to hunt for serious flaws, and many eyes are looking at the same high-value targets.

"It is very likely that some actor groups may have being using these vulnerabilities and led to the result of the attacks being observed by other information security vendors," Devcore member Bowen Hsu told Reuters.

But the security industry has been abuzz with other theories, including a hack of Microsoft's systems for tracking bugs, which has happened in the past.

© Thomson Reuters 2021


Are Amazonbasics TVs Good Enough to Beat Mi TVs in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Microsoft, ESET
Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi 17C Debuts With MediaTek Helio G81 Ultra Chip, 5,160mAh Battery
  2. Everything New in Apple's iOS 27 Developer Beta 2 Update for iPhone
  3. Motorola Edge 70 Max Design, Key Specifications Surface Online
  4. RedMagic Gaming Tablet 5 Pro Set to Launch on This Date
  5. Realme P4x Debuts With 8,000mAh Battery and 4G Connectivity
  6. The Oppo Reno 16 and Reno 16c Could Launch in India on This Date
  7. Here's When the Samsung Galaxy M47 5G Will Launch in India
  8. Samsonite's Latest Tracking Feature Is Designed to Help You Find Your Luggage
  9. Here's How Much the Upcoming Vivo X Fold 6 Might Cost
  1. Crypto Sector Sees Record 83 Hacks in Q2 2026, Most-Exploited Quarter to Date: Report
  2. Capcom Spotlight Broadcast Announced for June 25; Onimusha: Way of the Sword to Get New Look
  3. Asus ROG Zephyrus Duo, G14, G16, ProArt PZ14 and TUF Gaming A14 Go on Sale in India: Prices Start at Rs 1.99 Lakh
  4. Taiko Urges Users to Move Funds Following $1.7 Million Bridge Exploit
  5. Samsonite Zipprix FT Suitcase Unveiled With Built-In Waypoint Luggage Tracking System: Price, Features
  6. Redmi 17C Launched With 5,160mAh Battery, MediaTek Helio G81 Ultra Chip: Price, Features
  7. Hideo Kojima's Horror Title OD Will Feature 'New Game System' That Pushes Users to Keep Playing
  8. Vivo X Fold 6 Price, Storage Variants and Key Specifications Leaked Ahead of June 26 Launch in China
  9. Realme P4x Launched With 8,000mAh Battery, 6.8-Inch Display and 4G Connectivity: Price, Specifications
  10. WhatsApp Desktop, WhatsApp Web Users Targeted Using Malware Campaign, Kaspersky Warns
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.