logo

MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted Attacks

ID: b540443d-31e5-58cf-aaa5-9839078bd7fa

STIX ID: report--b540443d-31e5-58cf-aaa5-9839078bd7fa

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-22

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

An unknown actor is exploiting patched ProxyShell flaws in Microsoft Exchange (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to inject a keylogger into logon.aspx that captures credentials to a web-accessible file; Positive Technologies identified over 30 victims across government, banking, IT and education in Africa and the Middle East and recommends updating Exchange and searching for injected clkLgn() code and the stolen-data file path.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.