Russian Agents Have Been Hacking Major Email Program: NSA

The Exim exploit allows an attacker to gain access using specially crafted email and install programs, modify data and create new accounts — gaining a foothold on a compromised network.

Advertisement
By Associated Press | Updated: 29 May 2020 12:12 IST
Highlights
  • Exim email server is widely used
  • The exploit was identified 11 months ago, when a patch was issued
  • The NSA did not say who the Russian military hackers have targeted

The Exim exploit allows an attacker to gain access using specially crafted email

Photo Credit: Reuters

The US National Security Agency says the same Russian military hacking group that interfered in the 2016 presidential election and unleashed a devastating malware attack the following year has been exploiting a major email server program since last August or earlier. The timing of the agency's advisory Thursday was unusual considering that the critical vulnerability in the Exim Mail Transfer Agent — which mostly runs on Unix-type operating systems — was identified 11 months ago, when a patch was issued.

Exim is so widely used — though far less known than such commercial alternatives as Microsoft's proprietary Exchange — that some companies and government agencies that run it may still not have patched the vulnerability, said Jake Williams, president of Rendition Infosec and a former US government hacker.

It took Williams about a minute of online probing on Thursday to find a potentially vulnerable government server in the UK.

Advertisement

He speculated that the NSA might have issued an advisory to publicise the IP addresses and a domain name used by the Russian military group, known as Sandworm, in its hacking campaign — in hopes of thwarting their use for other means.

Advertisement

The Exim exploit allows an attacker to gain access using specially crafted email and install programs, modify data and create new accounts — gaining a foothold on a compromised network.

The NSA did not say who the Russian military hackers have targeted. But senior US intelligence officials have warned in recent months that Kremlin agents are engaged in activities that could threaten the integrity of the November presidential election.

Advertisement

An NSA official reached by The Associated Press would only say that the agency is publicising the vulnerability because, despite an October warning by British officials, it “has continued to be exploited and needs to be patched.” The hope, in now publicising Sandworm's role, is to further motivate patching, said the official, who spoke on condition they not be further identified.

Sandworm agents, tied to Russia's GRU military intelligence arm, caused great damage to the 2016 US presidential election, stealing and exposing Democratic National Committee emails and breaking into voter registration databases.

Advertisement

They also have been blamed by the US and UK governments for the June 2017 NotPetya cyber attack, which targeted businesses that operate in Ukraine. It caused at least $10 billion (roughly Rs. 75,612 crores) in damage globally, most notably to the Danish shipping multinational Maersk.


Is Redmi Note 9 Pro Max the best affordable camera phone in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: NSA, Hackers, Russian Hackers
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15 Launched With Snapdragon 8 Elite Gen 5 SoC at This Price
  2. Oppo Find X9 Series Launching Today: All You Need to Know
  3. Moto X70 Air Launch Teased for India: Price, Specifications Expected
  4. iQOO 15 Confirmed to Launch in India on This Date
  5. Battlefield 6's Free-to-Play Battle Royale Mode Launches October 28
  6. Wobble Will Launch Its First Smartphone in India on This Date
  7. Elon Musk's Grokpedia v0.1 Wants to Take Over Wikipedia Reign
  8. iPhone 17 Review
  9. Vivo X300 Series May Launch in India With Zeiss Telephoto Extender Kits
  10. Google's Fitbit AI Health Coach Uses Gemini Models
  1. OpenAI Explains How It Assesses Mental Health Concerns of ChatGPT Users, Sparks Backlash
  2. Oppo Find X9 Series India Launch Teased Hours Ahead of Global Debut; Exchange Offers, Other Benefits Revealed
  3. iQOO Neo 11 Confirmed to Launch With Snapdragon 8 Elite SoC, 8K VC Cooling Solution
  4. Wobble Announces Launch Date for First Smartphone in India: Expected Specifications, Features
  5. Lava Teases Upcoming Smartphone Launch in India; Lava Agni 4 Likely to Make Its Debut Soon
  6. Apple's iPhone 20 to Feature All Solid-State Haptic Buttons in 2027, Tipster Claims
  7. Samsung Galaxy Z Fold 8 Said to Feature Larger Battery, Reintroduce S-Pen Support
  8. Battlefield Redsec, Battlefield 6's Free-to-Play Battle Royale Mode, Arrives October 28
  9. Bitcoin Slips Below $114,000 as Traders Remain Cautious Amidst Market Uncertainty
  10. Samsung Galaxy Z TriFold Officially Showcased at APEC Summit Ahead of Launch: Report
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.