Hackers Using Automated Attack to Exploit Exchange Server and SQL Injection Vulnerabilities

[correlate]

Level 18
Thread author
Verified
Top Poster
Well-known
May 4, 2019
825
Recently, cybersecurity analysts at Prodraft's threat intelligence team detected that the hacker group FIN7 was actively exploiting vulnerabilities in Microsoft Exchange and SQL injection through an automated attack system in an attempt to perform the following illicit activities

 

[correlate]

Level 18
Thread author
Verified
Top Poster
Well-known
May 4, 2019
825
The notorious FIN7 hacking group uses an automated attack system that exploits Microsoft Exchange and SQL injection vulnerabilities to breach corporate networks, steal data, and select targets for ransomware attacks based on financial size.

This system was discovered by Prodaft's threat intelligence team, which has been closely following FIN7 operations for years now.
In a report shared with BleepingComputer before publication, Prodaft reveals details about FIN7's internal hierarchy, affiliations with various ransomware projects, and a new SSH backdoor system used for stealing files from compromised networks.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top