Thursday, March 11, 2021
As we alerted our readers last week, Microsoft announced that its Exchange email servers have been compromised, which is estimated to affect at least 30,000 companies based in the United States. It is reported that the hackers installed web shells (and sometimes multiple web shells) into Microsoft’s customers’ email servers, giving the hackers back doors into the victims’ email content. These web shells allow the attackers to have complete remote control over the victims’ emails and to access other information technology assets of the victims. This means they can access all the data contained in the emails and can plant malware or ransomware directly into a company’s system without having to use a phishing attack that would rely on an employee to introduce the malicious code into the system.