Exchange Mutation. How We Caught Anomalies in Outlook Pages

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Exchange Mutation. How We Caught Anomalies in Outlook Pages 😮
Continuing our series of incident investigation stories (you can read about them here, here, and partially listen here), we decided to analyze the general concept of injecting malicious code into Microsoft Outlook authentication pages. The result:
• In addition to the keylogger discovered during incident investigations, we found many other similar malware samples.
• The key difference among all malicious code fragments lies in the method of sending victims’ credentials: they use saving data to a file on the server, DNS tunneling, sending messages to a Telegram bot, and other techniques.
• Infections were detected in 26 countries. Most compromised servers are located in Vietnam, China, Russia, and Taiwan.
• According to statistics, the main reason for successful attacks on servers is the lack of installed security updates; on 3 out of 65 servers, updates had been missing since 2013.
📫 Which keyloggers were discovered, where and how hackers send victims’ data, and how to detect malicious code in an Outlook page, we detailed in our research.
#TI #IR #Malware
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…






