CI has taken two new steps in response to the Exchange Server compromise.
1. We hosted a panel discussion, which you can watch on this page.
2. We sent another communication to our Managed Detection and Response customers. We are posting the communication here in hopes that it helps others:
The Microsoft Exchange compromise has taken a new turn, with ransomware criminals now exploiting it, according to several reports, including Microsoft’s Security Intelligence Center. While this was expected, today is a good day to make sure you are prepared.
As a reminder, this is only impacting organizations with on-premises Exchange Servers, but it appears to affect all versions of Exchange from 2010 onwards and the risk of compromise before the patch is applied must be carefully evaluated.
Previously, criminals and/or state actors had compromised Exchange but had not taken action beyond downloading accessible data (commonly Outlook Address Book information) and implanting web shells. It now appears that at least 10 nefarious groups are using the vulnerability to inject malware and ransomware into systems.
Patching and Rebuilding
All organizations with on-prem Exchange servers should have patched by now and looked for indicators of compromise.
If you have patched and/or rebuilt your server and have had no indicators detected on your systems, there’s a good chance the criminals will not be able to lock up your network. But, if they were in your system at one point – if they were able to implant code onto servers, access files and data, or conceivably pivot from your Exchange server further inside your network - there is risk they have an undetected backdoor.
If you have an on-prem Exchange Server, make sure you:
What Critical Insight is Doing
The Critical Insight Operations Center is monitoring all Managed Detection and Response customers for lateral movement and other signs of malicious activity. We are carefully watching for emerging IOCs to implement into our monitoring to help us identify exploits as early as possible. While we are always vigilant, we are on elevated alert.
CI is adding resources to help customers respond, should the need arise.
Stay calm, stay safe, be prepared, and if CI can assist, we are here for you.