Hackers broke into U.S. military contractor, stole sensitive data

A joint alert by CISA, the FBI, and the NSA revealed a cyberattack in which spies hid and stole sensitive data from a U.S. contractor’s corporate network for several months.

It remains unknown how the hackers broke into the defense organization’s Microsoft Exchange Server. The warning said that the threat actors spent hours searching mailboxes and using a compromised admin account to query Exchange through its EWS API.

Other malicious activities carried out by the hackers include executing Windows commands to learn more about IT setup and collecting other files in archives using WinRAR, as well as using the Impacket open-source network toolkit to remotely control machines on the network and move laterally.

The attackers then used a custom data exfiltration tool called CovalentStealer to siphon sensitive data, including contract-related information from shared drives.

The attackers’ activities were only discovered after someone realized something was wrong. As part of the investigation conducted by CISA and a “trusted third-party” security firm, officials investigated malicious network activity and discovered that some unnamed crews gained initial access to the organization’s Exchange Server as early as mid-January 2021.

The researchers’ findings showed that the attackers exploited several Microsoft bugs in 2021, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065, to install 17 China Chopper webshells on the Exchange Server.

The sources for this piece include an article in TheRegister.

IT World Canada Staff
IT World Canada Staff
The online resource for Canadian Information Technology professionals.

Would you recommend this article?


Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.

Jim Love, Chief Content Officer, IT World Canada

Featured Download

ITW in your inbox

Our experienced team of journalists and bloggers bring you engaging in-depth interviews, videos and content targeted to IT professionals and line-of-business executives.

More Best of The Web