BusinessMirror
  • News
    • News
    • Top News
    • Regions
    • Nation
    • World
    • Asia Today
  • Business
    • Business
    • Agri-Commodities
    • Asean Economic Community
    • Banking & Finance
    • Companies
    • Economy
    • Entrepreneur
    • Executive Views
    • Export Unlimited
    • Harvard Management Update
    • Monday Morning
    • Mutual Funds
    • Stock Market Outlook
    • The Integrity Initiative
  • Sports
  • Opinion
    • Opinion
    • Columns
    • Editorial
    • Editorial cartoon
  • Life
    • Life
    • Art
    • Design&Space
    • Digital Life
    • Journey
    • Motoring
    • 360° Review
    • Property
    • Show
    • Tech
    • Tourism
    • Y2Z
  • Features
    • Biodiversity
    • Education
    • Envoys & Expats
    • Explainer
    • Faith
    • Green
    • Health & Fitness
    • Mission: PHL
    • Our Time
    • Perspective
    • Photo Gallery
    • Science
    • Today in History
    • Tony&Nick
    • When I Was 25
    • Wine & Dine
  • BMPlus
    • BMPlus
    • SoundStrip
    • Live & In Quarantine
    • Bulletin Board
    • Marketing
    • Public Service
    • CSR
  • The Broader Look
Subscribe
BusinessMirror
BusinessMirror
  • News
    • News
    • Top News
    • Regions
    • Nation
    • World
    • Asia Today
  • Business
    • Business
    • Agri-Commodities
    • Asean Economic Community
    • Banking & Finance
    • Companies
    • Economy
    • Entrepreneur
    • Executive Views
    • Export Unlimited
    • Harvard Management Update
    • Monday Morning
    • Mutual Funds
    • Stock Market Outlook
    • The Integrity Initiative
  • Sports
  • Opinion
    • Opinion
    • Columns
    • Editorial
    • Editorial cartoon
  • Life
    • Life
    • Art
    • Design&Space
    • Digital Life
    • Journey
    • Motoring
    • 360° Review
    • Property
    • Show
    • Tech
    • Tourism
    • Y2Z
  • Features
    • Biodiversity
    • Education
    • Envoys & Expats
    • Explainer
    • Faith
    • Green
    • Health & Fitness
    • Mission: PHL
    • Our Time
    • Perspective
    • Photo Gallery
    • Science
    • Today in History
    • Tony&Nick
    • When I Was 25
    • Wine & Dine
  • BMPlus
    • BMPlus
    • SoundStrip
    • Live & In Quarantine
    • Bulletin Board
    • Marketing
    • Public Service
    • CSR
  • The Broader Look
  • World

Microsoft Exchange used to hack diplomats before breach in 2021

  • Bloomberg News
  • August 8, 2021
  • 2 views
  • 6 minute read
Total
0
Shares

Late last year, researchers at the Los Angeles-based cyber-security company Resecurity stumbled across a massive trove of stolen data while investigating the hack of an Italian retailer.

Squirreled away on a cloud storage platform were five gigabytes of data that had been stolen during the previous three and half years from foreign ministries and energy companies by hacking their on-premises Microsoft Exchange servers. In all, Resecurity researchers found documents and e-mails from six foreign ministries and eight energy companies in the Middle East, Asia and Eastern Europe.

The attacks, which haven’t been previously reported, served as a prequel to a remarkably similar, widely publicized hack of Microsoft Exchange servers from January to March of this year, according to Resecurity. A person familiar with the investigation into the 2021 attack, who wasn’t authorized to speak publicly and requested anonymity, made a similar allegation, saying the data theft discovered by Resecurity followed the same methods. The 2021 hack was extraordinary for its scope, infecting as many as 60,000 global victims with malware.

Microsoft quickly pinned the 2021 cyber attack on a group of Chinese state-sponsored hackers it named Hafnium, and the US, UK, and their allies made a similar claim last month, attributing it to hackers affiliated with the Chinese government.

Resecurity can’t say for sure the same group perpetrated the attacks. Even so, the cache of documents contained information that would have been of interest to the Chinese government, according to Gene Yoo, Resecurity’s chief executive officer. The person familiar said the victims selected by the hackers and type of intelligence gathered by attackers also pointed to a Chinese operation.

Researchers at other cyber-security firms, who requested anonymity because they hadn’t reviewed all of Resecurity’s findings, cautioned that the attacks could have been perpetrated by any number of nations interested in Middle East diplomacy and the internal communications of influential energy companies.

Regardless, both hacking campaigns underscore how flaws in Microsoft’s popular on-premises e-mail servers—which are controlled by the customers using those systems—have for years acted as a skeleton key for hackers to unlock sensitive data from government and private companies.

The Chinese government rejected allegations that its state-sponsored hackers were involved in any of these attacks.

“China resolutely opposes any form of online attack or infiltration. This is our clear and consistent stance,” the Ministry of Foreign Affairs said, in a messaged statement. “Relevant Chinese laws on data collection and handling clearly safeguards data security and strongly oppose cyber attacks and other criminal activity.”

In addition, the Ministry said it was a “complex technology problem” to determine the source of attacks, adding that it hoped the media would avoid “groundless speculation” and rely on “comprehensive evidence when determining the nature of cyberspace events.” China has already proposed a global data security standard and urges “all parties to work with us to genuinely safeguard global data security,” according to the Ministry’s statement.

Microsoft Corp. spokesperson Jeff Jones said in a statement that, “many nation-state actors” target e-mail systems to gain confidential information, and that Microsoft’s security teams are “constantly working with our security partners” to identify new vulnerabilities that could be used in future attacks.

Microsoft has been tracking Hafnium, the group it accused of the 2021 attack, since as early as April 2020, including collecting data about its cyber-espionage operations, Jones said. Microsoft’s threat intelligence unit has since tracked multiple campaigns by Hafnium, and have notified countries that were victims of the attacks, according to Jones, who didn’t identify the countries. Hafnium’s goal is espionage with a focus on data theft, he said.

In a series of breaches stretching from 2017 to 2020, hackers stole documents and e-mails from foreign ministries in Bahrain, Iraq, Turkey, Oman, Egypt and Jordan—and e-mail and data from eight energy companies, including Malaysian oil and gas giant Petronas Nasional Bhd and India’s Hindustan Petroleum Corp., according to Resecurity and a review of the stolen data by Bloomberg News.

Some of the e-mails and documents appear to contain sensitive information: diplomatic cables, critical network data including usernames and passwords and private consumer data.

For instance, one memo from an attaché from Bahrain described a December 9, 2018, meeting in which the country’s leading Asia diplomats met with Chinese counterparts, at a time when China was facing a possible special session of the United Nations Human Rights Council to scrutinize its treatment of Muslim Uyghurs. In the meeting, China’s Lin Jiming recalled that two years earlier, his country defended Bahrain’s own human-rights record during a formal UN review, according to the memo, which was forwarded to Bahrain’s foreign minister and human-rights affairs directorate, along with a recommendation to support China’s position.

Bahrain was among 37 countries that signed a letter in mid-2019 supporting China’s policies in the western region of Xinjiang. The special session never occurred.

There are also documents detailing day-to-day business, such as internal memos about personnel changes, news summaries, an autograph request for a foreign minister and invitations to diplomatic conferences, according to Resecurity and the documents reviewed by Bloomberg.

Officials in Bahrain didn’t respond to a message seeking comment. Officials in Iraq confirmed the government has been the target of cyber attacks but said they weren’t damaging. Representatives from Turkey, Oman, Egypt and Jordan didn’t respond to requests for comment. HPCL didn’t respond.

The attackers also compromised a series of mostly state-run energy companies, utilities and research facilities covering regions stretching from Eastern Europe to Southeast Asia, according to Resecurity. Along with sensitive administrative data and intellectual property, Resecurity’s researchers also found lists of users, their internal network permissions and password details, all of which could be used by hackers to expand their footprint inside victim networks, according to Resecurity researchers and the documents.

Inside the servers of Petronas, the hackers found lists of usernames and passwords, according to Resecurity and the documents. Within Hindustan Petroleum, they found thousands of user records and employee e-mails, according to the researchers and documents.

Other victims included Doosan Fuel Cell Co. in Korea; Romania’s Institute for Nuclear Research in Pitesti; the State Oil Company of Azerbaijan Republic, known as SOCAR; the UAE’s Sharjah National Lube Oil Corp. and Jordan’s Electric Distribution Company and National Electric Power Company, according to Resecurity.

In response to a Bloomberg query, Doosan said its Exchange server was attacked but that hackers were prevented from stealing any data. Petronas didn’t answer specific questions about the alleged attack but provided a statement about their “robust and comprehensive cyber-security strategy.”

The other companies and Romania’s nuclear research unit didn’t respond to requests for comment.

The 2021 attack occurred after hackers discovered a series of previously unknown vulnerabilities—called zero days—in the Microsoft Exchange e-mail system, and then used those to exploit tens of thousands of victims globally. While the attack’s sprawl was unprecedented, relatively few of the Exchange customers who were infected with malware were then targeted for more invasive attacks such as data theft or ransomware, Microsoft said in a blog.

It’s unclear how the hackers behind the earlier attacks on foreign ministries and energy companies initially infiltrated the networks.

But after the original compromise, both attacks were almost identical. Hackers installed web shells on victim networks that allowed them to remotely access the internal login page for each server. The attackers then used an open-source software called Mimikatz (and a modified version of Mimikatz) to steal passwords and establish a connection inside the network.

Such methods aren’t particularly unique. Instead, such generic attack methods allow hackers to hide their tracks and have become a signature for government hacking groups, including some affiliated with the Chinese government, said Ben Read, director of cyber-espionage analysis at the cybersecurity firm Mandiant.

The security research firm Cybereason Inc. published its own allegations about Chinese hackers this week. The firm alleged that at least five telecommunications giants were targeted by state-backed Chinese hackers in an operation also dating back to 2017. The hacking groups stole phone records and geolocation data by exploiting systems, including Microsoftt Exchange servers, according to a report published Aug. 3. The Chinese Foreign Ministry said the report “hypes political rumors” created by the US and its allies and are “fabricated out of nothing.”

0
0
0
0
0
0
0
0
Previous Article
  • World

Era of cheap natural gas ends as prices surge by 1,000 percent

  • Bloomberg News
  • August 6, 2021
Know more
Next Article
  • World

Hydrogen goes nuclear as UK reactor pivots toward renewables

  • Bloomberg News
  • August 8, 2021
Know more

Know more

Know more
  • 43
  • 3 min
  • World

Pentagon: Chinese fighter jet flew past nose of US aircraft

  • Peter Martin & Iain Marlow / Bloomberg News
  • May 31, 2023
Know more
  • 33
  • 4 min
  • World

Moscow drone attack exposes Russia’s vulnerabilities, fuels criticism of military

  • Associated Press
  • May 31, 2023
Know more
  • 35
  • 4 min
  • World

Nato to send 700 more troops to Kosovo to help quell violent protests

  • Zenel Zhinipotoku & Llazar Semini / The Associated Press
  • May 31, 2023
Know more
  • 180
  • 3 min
  • World

Debt ceiling deal faces final test in Congress to avert US default

  • Billy House, Steven T. Dennis & Laura Litvan / Bloomberg News
  • May 30, 2023
Know more
  • 130
  • 2 min
  • World

China launches new crew for space station

  • Associated Press
  • May 30, 2023
Know more
  • 125
  • 3 min
  • World

Dozens of Nato soldiers hurt in Kosovo in clash with Serbs

  • Misha Savic & Jasmina Kuzmanovic / Bloomberg News
  • May 30, 2023
Know more
  • 111
  • 2 min
  • World

9 injured in shooting near beach in Hollywood, Florida

  • Terry Spencer / The Associated Press
  • May 30, 2023
Know more
  • 118
  • 3 min
  • World

Imran Khan summoned over attacks on Army buildings

  • Faseeh Mangi & Ismail Dilawar / Bloomberg News
  • May 30, 2023
Know more
  • 149
  • 3 min
  • World

Russia’s pre-dawn air raid on Kyiv kills 1; Moscow attacked by drones

  • Susie Blann / The Associated Press
  • May 30, 2023
Know more
  • 128
  • 4 min
  • World

China rejects US claims over ‘de-risking’ not ‘decoupling’

  • Bloomberg News
  • May 30, 2023
Know more
  • 113
  • 1 min
  • World

Russia issues arrest warrant for US senator over Ukraine comments

  • Associated Press
  • May 30, 2023
Know more
  • 126
  • 3 min
  • World

China spurns US request for defense chiefs meeting at Singapore summit

  • Peter Martin / Bloomberg News
  • May 30, 2023
Know more
  • 115
  • 4 min
  • World

Spain PM’s shock election call brings unruly coalition to heel

  • BusinessMirror
  • May 30, 2023
Know more
  • 100
  • 5 min
  • World

Teenagers from Islamic State families undergo rehabilitation in Syria, but future still uncertain

  • Hogir Al Abdo & Bassem Mroue / The Associated Press
  • May 30, 2023
Know more
  • 99
  • 4 min
  • World

Staff at Ukraine’s experimental nuclear site pick up pieces from Russian strikes

  • Associated Press
  • May 30, 2023
Know more
  • 113
  • 2 min
  • World

At least 153 people arrested under special powers have died in Salvadoran prisons

  • Associated Press
  • May 30, 2023
Know more
  • 153
  • 5 min
  • World

In Nigeria’s north, families demand justice as armed men seek control

  • Chinedu Asadu Runji / The Associated Press
  • May 29, 2023
Know more
  • 144
  • 5 min
  • World

Drought-struck Barcelona quenches thirst by running desalination plant

  • Joseph Wilson / The Associated Press
  • May 29, 2023
Know more
  • 138
  • 5 min
  • World

Nighttime Russian drone attacks terrify citizens in Ukrainian capital

  • Samya Kullab / The Associated Press
  • May 29, 2023
Know more
  • 141
  • 5 min
  • World

Turkey’s Erdogan reelected, extends rule into 3rd decade

  • Suzan Fraser & Zeynep Bilginsoy / The Associated Press
  • May 29, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Subscribe

BusinessMirror
  • About Us
  • Contact Us
  • Advertise with us
  • Privacy Policy
  • Cookie Policy
  • Podcast
  • Text-Only Homepage

Input your search keywords and press Enter.