MICROSOFT Exchange servers have been backdoored by threat actors worldwide.

Attackers are using a new malware to access Microsoft Exchange servers belonging to military and government entities in Europe, the Middle East, Africa and Asia.

Microsoft Exchange servers worldwide have been backdoored by threat actors.

1

Microsoft Exchange servers worldwide have been backdoored by threat actors.Credit: Getty

Dubbed SessionManager, the malicious software poses as an Internet Information Services (IIS) module.

IIS is the legitimate web server installed by default on Microsoft Exchange servers. 

Typically, organizations enable IIS modules to streamline specific processes on their web infrastructure, per ARSTechnica.

Roughly 34 servers belonging to 24 organizations have been infected with SessionManager since March 2021, Security firm Kaspersky revealed.

Official warning for Internet Explorer users as Microsoft shuts down browser
Microsoft warning for BILLIONS as malicious files spotted – how to stay safe

As of June 2022, around 20 organizations remained infected, Kaspersky said in a blog post on Thursday.

What does SessionManager do?

SessionManager can accomplish a number of things for threat actors, according to a report by Bleeping Computer.

The malware can drop and manage arbitrary files on comprised servers, execute code remotely, and link the victim’s network to the bad actor’s network.

Most read in Tech

Kaspersky explained further: “The SessionManager backdoor enables threat actors to keep persistent, update-resistant and rather stealth access to the IT infrastructure of a targeted organization.”

“Once dropped into the victim’s system, cybercriminals behind the backdoor can gain access to company emails.”

They can also update malicious access by installing other types of malware or “clandestinely manage compromised servers, which can be leveraged as malicious infrastructure.”

How can I protect myself/my organization?

Backdoor attacks are difficult to detect, however, there are steps you can take to keep your device(s) safe.

For starters, use an Antivirus that can identify and prevent a wide range of malware, including trojans and spyware.

Be vigilant when downloading files from the internet as many of them can be compromised or loaded with malware.

Minecraft YouTuber passes away one year after cancer diagnosis
Denise and Charlie's daughter Lola, 17, involved in terrifying car crash

You will definitely also want to use a Firewall, which is considered essential for backdoor protection.

Firewalls monitor all incoming and outgoing traffic on your device – so if someone is trying to get into your device, the firewall will keep them out.

This post first appeared on Thesun.co.uk

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Over 1,000 fast radio bursts over a 47-day span are detected coming from a galaxy in deep space

An international group of researchers have discovered that more than 1,600 Fast…

I’m fuming after I was charged £180 for a ‘FREE’ app for my son – and I’m not the only one furious

A MUM has been left feeling outraged after being charged £180 for…

One of 5G’s Biggest Features Is a Security Minefield

True 5G wireless data, with its ultrafast speeds and enhanced security protections,…

Call of Duty has banned 350,000 players for ‘racist and toxic names and behaviour’

CALL of Duty has kicked hundreds of thousands of players to the…