MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted Attacks
ID: b540443d-31e5-58cf-aaa5-9839078bd7fa
STIX ID: report--b540443d-31e5-58cf-aaa5-9839078bd7fa
Feed Name: The Hacker News
Threat Score
An unknown actor is exploiting patched ProxyShell flaws in Microsoft Exchange (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to inject a keylogger into logon.aspx that captures credentials to a web-accessible file; Positive Technologies identified over 30 victims across government, banking, IT and education in Africa and the Middle East and recommends updating Exchange and searching for injected clkLgn() code and the stolen-data file path.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
