<!--DEBUG:--><!--DEBUG:dc3-united-states-software-in-english-pdf-2--><!--DEBUG:--><!--DEBUG:dc3-united-states-software-in-english-pdf-2--><!--DEBUG-spv-->{"id":1973190,"date":"2021-08-22T21:06:00","date_gmt":"2021-08-22T19:06:00","guid":{"rendered":"http:\/\/nhub.news\/?p=1973190"},"modified":"2021-08-22T23:03:26","modified_gmt":"2021-08-22T21:03:26","slug":"lockfile-ransomware-targets-microsoft-exchange-servers","status":"publish","type":"post","link":"http:\/\/nhub.news\/fr\/2021\/08\/lockfile-ransomware-targets-microsoft-exchange-servers\/","title":{"rendered":"LockFile Ransomware Targets Microsoft Exchange Servers"},"content":{"rendered":"<p style=\"text-align: justify;\"><b>A new ransomware family called LockFile has started targeting Microsoft Exchange servers via ProxyShell and PetitPotam.<\/b><br \/>\nSecurity researchers have discovered a new ransomware family called LockFile that appears to have been used to attack Microsoft Exchange servers in the U.S. and Asia since at least July 20. Symantec said when it revealed LockFile on Aug.20 that it found evidence of the ransomware targeting at least 10 organizations over the course of a single month. The security company said LockFile&rsquo;s operators used an attack called PetitPotam, which targets a domain controller to gain control over an entire network, but it didn&rsquo;t know how the attackers gained access to the servers. DoublePulsar&rsquo;s Kevin Beaumont did. He reported that his personal honeypot project\u2014an intentionally exposed server that can be used to learn more about hacking attempts\u2014was targeted by LockFile&rsquo;s operators on Aug.13 and Aug.16. Those attacks revealed that LockFile was exploiting a series of vulnerabilities in Microsoft Exchange known collectively as ProxyShell. ProxyShell is one of three collections of vulnerabilities affecting Microsoft Exchange discovered, exploited, and disclosed by Devcore principal security researcher Orange Tsai. The attack surfaces were shown off at the Pwn2Own hacking competition in April, and Tsai shared more information about them during a talk at the Black Hat 2021 conference on Aug.5 as well. Microsoft patched these vulnerabilities in May, but BleepingComputer reported that researchers and hackers alike have been able to recreate the exploit, which is now being used to enable the LockFile attacks. The ransomware&rsquo;s operators can also target Exchange servers that haven&rsquo;t received the latest updates and therefore remain vulnerable to the original ProxyShell attacks. Beaumont said there were still \u00ab\u00a0hundreds of directly exploitable, internet facing systems with *.gov SSL certificate hostnames\u00a0\u00bb in the U.S. as of Aug.21 and cited TechTarget&rsquo;s report that \u00ab\u00a0tens of thousands of Exchange servers are still vulnerable to ProxyLogon and ProxyShell.\u00a0\u00bb Some of those are likely to be honeypots, according to the report, but most probably aren&rsquo;t. The U.S. Cybersecurity and Infrastructure Security Agency said it \u00ab\u00a0strongly urges organizations to identify vulnerable systems on their networks and immediately apply Microsoft&rsquo;s Security Update from May 2021\u2014which remediates all three ProxyShell vulnerabilities\u2014to protect against these attacks.\u00a0\u00bb Microsoft has also shared methods of mitigating the PetitPotam attack. LockFile itself reportedly encrypts all of the files on a target system, renames them with the \u00ab\u00a0.lockfile\u00a0\u00bb extension, and then shows a note telling the victims to contact the ransomware&rsquo;s operators via email to negotiate the cost of recovering their files. That note is said to resemble one used by the LockBit ransomware group and to include a reference to the Conti Gang as well.<\/p>\n<script>jQuery(function(){jQuery(\".vc_icon_element-icon\").css(\"top\", \"0px\");});<\/script><script>jQuery(function(){jQuery(\"#td_post_ranks\").css(\"height\", \"10px\");});<\/script><script>jQuery(function(){jQuery(\".td-post-content\").find(\"p\").find(\"img\").hide();});<\/script>","protected":false},"excerpt":{"rendered":"<p>A new ransomware family called LockFile has started targeting Microsoft Exchange servers via ProxyShell and PetitPotam. Security researchers have discovered a new ransomware family called LockFile that appears to have been used to attack Microsoft Exchange servers in the U.S. and Asia since at least July 20. Symantec said when it revealed LockFile on Aug.20 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1973189,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[93],"tags":[],"_links":{"self":[{"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/posts\/1973190"}],"collection":[{"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/comments?post=1973190"}],"version-history":[{"count":1,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/posts\/1973190\/revisions"}],"predecessor-version":[{"id":1973191,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/posts\/1973190\/revisions\/1973191"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/media\/1973189"}],"wp:attachment":[{"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/media?parent=1973190"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/categories?post=1973190"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/tags?post=1973190"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}