Epsilon Red – more than 3.5 thousand servers are still vulnerable
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-1472 | Unauthenticated Privilege Escalation (Zerologon) in Microsoft Netlogon Domain Controllers CVE-2020-1472, widely known as "Zerologon," is an elevation-of-privilege flaw in how the Netlogon secure channel is established over the Netlogon Remote Protocol (MS-NRPC) on Microsoft domain controllers. An unauthenticated attacker with network reachability to a domain controller sends specially crafted Netlogon messages to establish a vulnerable secure channel and then runs a specially crafted application on the network to obtain domain administrator access. Successful exploitation yields domain administrator privileges, effectively full compromise of the Active Directory environment, and the flaw is known to be used in ransomware operations. Any organization running affected Windows Server versions (2008 through 20H2) as domain controllers is exposed, along with environments using Netlogon implementations from Samba and distributions or products from Fedora, openSUSE, Canonical (Ubuntu), Debian, Synology, and Oracle. Exploitation is highly active: a public Zerologon PoC/exploit is available, the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, with known ransomware use), and EPSS estimates a 99.4% probability of exploitation within 30 days. Do: Apply the vendor updates on all domain controllers and other affected systems immediately, following Microsoft's two-phase Netlogon secure channel guidance (the enforcement phase of the phased rollout began in Q1 2021). Audit Netlogon secure-channel connections and event logs for clients still using vulnerable connections before enabling full enforcement, and install updated packages for Samba and other Netlogon implementations from Fedora, openSUSE, Ubuntu, Debian, Synology, and Oracle. Given known ransomware use, prioritize patching any domain controller reachable from user networks, VPNs, or the internet. | 5.5 | 99% | KEV ransomware PoC |
| massmillions of domain controllers worldwide (essentially every Active Directory domain), with hundreds of thousands of domain controllers/RPC endpoints… | |
| CVE-2021-26855 +1 in the same advisory: …27065 | Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon) CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing. Do: Apply the vendor's March 2021 Exchange security updates (or later cumulative updates) immediately, per the CISA required action; until patched, limit Exchange (ECP/OWA) exposure to the internet via firewall/VPN rules. Hunt for compromise: review IIS logs for unrecognized authenticated activity against FrontEnd HttpProxy endpoints, and check for malicious files or webshells under inetpub\wwwroot\aspnet_client, given the known ransomware use. | 9.1 group max | 100% | KEV ransomware PoC ×4 |
| masshundreds of thousands of on-premises deployments; tens of thousands of internet-exposed Exchange servers |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| url | http://[redacted | ou have two options : 1. Chat with me : -Visit our website: hxxp://[redacted]/support/NegotiationArea/[redacted]/ -When you visit our we |
Full article930 words · extracted from securityaffairs.com · click to collapse

CyberNews researchers analyzed the recently discovered Epsilon Red operations and found that more than 3.5K servers are still vulnerable
Several weeks later, security researchers from Sophos have discovered a new ransomware variant known as Epsilon Red. Now, we know exactly how it was carried out – and what you should do to be safe from it.
Seemingly, a variant of the ransomware, Epsilon Red, relies on vulnerable Microsoft Exchange servers. Threat actors use them to launch mass server exploitation campaigns and try to expose companies’ information for revenue.
It works: one of the victims has already paid over $200,000 in Bitcoin, setting a dangerous precedent of companies giving into the demands of cyber criminals to prevent a possible data leak and damage to their reputation and loss of operations due to crippled IT services after important file encryption.
We have some basic information about REvil, another ransomware group that employs affiliates to launch attacks and has a similar ransom note to Epsilon Red, after having applied to work with the ransomware group earlier this year. We’ve also covered the Epsilon Red variant on CyberNews. Now, we have some additional information, including the vulnerabilities it uses and the servers it affects.
Research findings
During our research, we checked all publicly obtainable sources offering actionable intelligence on Epsilon Red. Our findings suggest that the new ransomware variant appears to be properly detected by the majority of leading antivirus vendors.
This specific ransomware variant is attempting to propagate using a variety of recently discovered Microsoft Exchange server vulnerabilities, such as CVE-2020-1472, CVE-2021-26855, CVE-2021-27065 to drop ransomware on the affected hosts.
We found 695 vulnerable ZeroLogon servers in the US, additional 71 vulnerable servers in Australia, and 36 more in Argentina. These servers are directly susceptible and exploitable by the Epsilon Red ransomware campaign.

Where are the IoCs (Indicators of Compromise)?
We found some of the host based IoC’s (Indicators of Compromise) during an investigation. From our research, we can conclude that this appears to be yet another copycat ransomware release. The operators behind the Epsilon Red variant are attempting to gain traction and get as many infections as possible..
A ransom note appears to be similar to the original ransom note presented by the REvil ransomware, barring a few grammatical fixes.

“[+] What’s Happened? [+]
Your files have been encrypted and currently unavailable. You can check it. All files in your system have “EpsilonRed” extension. By the way, everything is possible to recover (restore) but you should follow our instructions. Otherwise you can NEVER return your data.
[+] What are our guarantees? [+]
It’s just a business and we care only about getting benefits. If we don’t meet our obligations, nobody will deal with us. It doesn’t hold our interest. So you can check the ability to restore your files. For this purpose you should come to talk to us we can decrypt one of your files for free. That is our guarantee. It doesn’t metter for us whether you cooperate with us or not. But if you don’t, you’ll lose your time and data cause only we have the private key to decrypt your files. time is much more valuable than money.
[+] Data Leak [+]
We uploaded your data and if you dont contact with us then we will publish your data.
Example of data:
– Accounting data
– Executive data
– Sales data
– Customer support data
– Marketing data
– And more other …
[+] How to Contact? [+]
You have two options :
1. Chat with me :
-Visit our website: hxxp://[redacted]/support/NegotiationArea/[redacted]/
-When you visit our website, put the following KEY into the input form.
-Then start talk to me.
2. Email me at : [redacted]@protonmail.com
KEY:
–
!!! DANGER !!!
DON’T try to change files by yourself, DON’T use any third party software or antivirus solutions to restore your
data – it may entail the private key damage and as a result all your data loss!
!!! !!! !!!
ONE MORE TIME: It’s in your best interests to get your files back. From our side we ready to make everything for
restoring but please do not interfere.
!!! !!! !!”
How to stay safe from Epsilon Red?
If faced with a ransom demand, the affected party should immediately report the ransomware email to the law enforcement.
The next key factor is to have a proper defense in-depth protection strategy. This includes the use of zero-knowledge online backup of crucial information. If cybercriminals cannot access sensitive information, they will have nothing to blackmail the company with. Keep in mind that prevention is a much more practical solution than cure.
The recently implemented Ransomware Task Force is a step in the right direction. However, a more pragmatic way to ransomware scams that would employ a central information sharing database should also be considered in the future.
This would allow for using actual information for research purposes, reaching out to law enforcement in a systematic way, and presenting actionable intelligence on cyber threat actors to leading antivirus vendors.
What users and organizations should keep in mind when dealing with cryptoviral extortion – today’s modern ransomware threat – is not to pay the actual amount and rely on zero-knowledge online backup for crucial business and personal information. The fewer payments the criminals will get, the fewer threats they will pose in the future.
Original post @ https://cybernews.com/security/epsilon-red-research-over-3500-servers-are-still-vulnerable/
About the author: CyberNews Team
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, ransomware)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/119415/security/epsilon-red-vulnerable-servers.html