Prometei Botnet Exploits Exchange Server Bugs to Grow
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-27065 +1 in the same advisory: …26858 | ProxyLogon chain RCE in Microsoft Exchange Server (CVE-2021-27065) CVE-2021-27065 is a remote code execution vulnerability in on-premises Microsoft Exchange Server, best known as the file-write component of the ProxyLogon exploit chain disclosed in March 2021. The flaw lets an attacker write arbitrary files, such as web shells, to the Exchange web server, and when chained with the pre-authentication SSRF bug in the same ProxyLogon chain it yields fully unauthenticated code execution on the server. Successful exploitation gives attackers the ability to run commands as the Exchange server, access organizational email and data, establish persistence, and — as CISA notes — it has been used as a foothold for ransomware deployment. Any organization running an affected on-premises Exchange Server is exposed, particularly when Outlook Web Access or other Exchange endpoints are internet-reachable; this is a server-product flaw, not an Exchange Online/cloud-mailbox issue. Exploitation is confirmed and widespread: it is in the wild with known ransomware use, CISA added it to the KEV on 2021-11-03, and EPSS assigns a ~99.9% probability of exploitation within 30 days. Do: Apply Microsoft's March 2021 (or later) Exchange Server security updates immediately, consistent with CISA's required action to apply vendor updates. Hunt for ProxyLogon indicators — web shells under the Exchange FrontEnd HttpProxy folders (e.g., in owa/auth), unexpected files in the OAB virtual directory, and ransomware artifacts — using Microsoft's Safety Scanner or the Test-ProxyLogon tooling, and treat any hit as a full intrusion (scope persistence and rotate exposed credentials). If patching must be deferred, restrict or remove internet exposure of OWA/ECP and apply interim mitigations while monitoring for ransomware deployment. | 7.8 | 100% | KEV ransomware PoC ×2 |
| mass≈300,000–600,000 internet-exposed on-prem Exchange servers (order of magnitude: hundreds of thousands) |
Full article395 words · extracted from infosecurity-magazine.com · click to collapse
Security researchers have discovered that a persistent cryptocurrency mining botnet is exploiting still-unpatched Microsoft Exchange servers to grow globally.
Dubbed “Prometei,” the botnet was first reported on in July 2020 and is thought to have been around since 2016, according to Cybereason Nocturnus.
However, the research team found a new development in that the threat actors behind it have been exploiting Microsoft Exchange vulnerabilities CVE-2021-27065 and CVE-2021-26858 to penetrate victim networks, steal credentials and install malware.
These bugs are part of the four zero-days patched by Microsoft back in March after being exploited by Chinese APT group Hafnium.
“The victimology is quite random and opportunistic rather than highly targeted, which makes it even more dangerous and widespread. Prometei has been observed to be active in systems across a variety of industries, including: finance, insurance, retail, manufacturing, utilities, travel, and construction,” senior threat researcher Lior Rochberger of Cybereason noted in a blog post today.
“It has been observed infecting networks in the US, UK and many other European countries, as well as countries in South America and East Asia. It was also observed that the threat actors appear to be explicitly avoiding infecting targets in former Soviet bloc countries.”
After initial exploitation, the botnet is designed to spread across the network in order to install a Monero miner on as many endpoints as possible. To do this, it uses tried-and-tested exploits EternalBlue and BlueKeep, as well as harvesting credentials, and exploiting SMB and RDP alongside other components such as SSH client and SQL spreader, Rochberger said.
Four separate command-and-control (C&C) servers add resilience and make it harder to disrupt the botnet, he added. Prometei is also designed to use Windows or Linux payloads to compromise individual endpoints depending on their OS.
Assaf Dahan, Cybereason senior director and head of threat research, argued that the botnet poses a serious risk as it has been under-reported in the past.
“When the attackers take control of infected machines, they are not only capable of mining bitcoin by stealing processing power, but could exfiltrate sensitive information as well,” he added.
“If they desire to do so, the attackers could also infect the compromised endpoints with other malware and collaborate with ransomware gangs to sell access to the endpoints. To make matters worse, crypto-mining drains valuable network computing power, negatively impacting business operations and the performance and stability of critical servers.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/prometei-botnet-exploits-exchange/