Hackers broke into U.S. military contractor, stole sensitive data

Share post:

A joint alert by CISA, the FBI, and the NSA revealed a cyberattack in which spies hid and stole sensitive data from a U.S. contractor’s corporate network for several months.

It remains unknown how the hackers broke into the defense organization’s Microsoft Exchange Server. The warning said that the threat actors spent hours searching mailboxes and using a compromised admin account to query Exchange through its EWS API.

Other malicious activities carried out by the hackers include executing Windows commands to learn more about IT setup and collecting other files in archives using WinRAR, as well as using the Impacket open-source network toolkit to remotely control machines on the network and move laterally.

The attackers then used a custom data exfiltration tool called CovalentStealer to siphon sensitive data, including contract-related information from shared drives.

The attackers’ activities were only discovered after someone realized something was wrong. As part of the investigation conducted by CISA and a “trusted third-party” security firm, officials investigated malicious network activity and discovered that some unnamed crews gained initial access to the organization’s Exchange Server as early as mid-January 2021.

The researchers’ findings showed that the attackers exploited several Microsoft bugs in 2021, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065, to install 17 China Chopper webshells on the Exchange Server.

The sources for this piece include an article in TheRegister.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Cisco Duo’s Multifactor Authentication service compromised by social engineering attack

Cisco Duo, a prominent provider of multifactor authentication (MFA) services, has fallen victim to a cyberattack targeting one...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways