FBI deletes web shells from hundreds of compromised Microsoft Exchange servers before alerting admins
- Reference: 1618367212
- News link: https://www.theregister.co.uk/2021/04/14/fbi_exchange_server_malware_deletion/
- Source link:
The Feds were given [1]approval by the courts to carry out the deletions, which occurred without first warning the servers' owners, following the discovery and exploitation of critical vulnerabilities in the enterprise software.
[2]
Shortly after Microsoft [3]raised the alarm early last month over the security holes in Exchange and provided fixes for the vulnerabilities, miscreants [4]swarmed to exploit the programming blunders and hijack unpatched installations. (Certain groups were even breaking in Exchange servers via the holes before their existence was public knowledge.)
The FBI found hundreds of such compromised deployments with backdoors installed by one cyber-gang in particular, leading to agents asking the courts to allow them to go in and delete the malicious code. The court approved the action and the document was unsealed this week, 30 days later.
[5]
NSA helps out Microsoft with critical Exchange Server vulnerability disclosures in an April shower of patches [6]READ MORE
“Although many infected system owners successfully removed the web shells from thousands of computers, others appeared unable to do so, and hundreds of such web shells persisted unmitigated,” the Justice Department noted in an announcement. “Today’s operation removed one early hacking group’s remaining web shells, which could have been used to maintain and escalate persistent, unauthorized access to US networks.”
The FBI deleted the shells by issuing a command through the web shell to the server “which was designed to cause the server to delete only the web shell (identified by its unique file path),” it said. Critically, however, the Feds did not touch the servers themselves and so they remain unpatched and open to infiltration.
Cybersecurity joint effort
The FBI said it will try to send emails to the operators of all the servers it discovered the web shells on, advising them how to patch their equipment.
“Today’s court-authorized removal of the malicious web shells demonstrates the Department’s commitment to disrupt hacking activity using all of our legal tools, not just prosecutions,” said assistant attorney general John Demers from the Justice Department’s National Security Division.
“Combined with the private sector’s and other government agencies’ efforts to date, including the release of detection tools and patches, we are together showing the strength that public-private partnership brings to our country’s cybersecurity.”
The action was [7]approved [PDF] in a Texas court and the acting US Attorney of the Southern District of Texas, Jennifer Lowery, pitched the deletion as the sort of coordination between government and the private sector that is needed to effectively combat cybersecurity threats.
“This court-authorized operation to copy and remove malicious web shells from hundreds of vulnerable computers shows our commitment to use any viable resource to fight cyber criminals,” she said.
[8]
“We will continue to do so in coordination with our partners and with the court to combat the threat until it is alleviated, and we can further protect our citizens from these malicious cyber breaches.” ®
Get our [9]Tech Resources
[1] https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-effort-disrupt-exploitation-microsoft-exchange
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YHZo3CWRcf5easAHDNLD4wAAAEc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/
[4] https://www.theregister.com/2021/03/15/in_brief_security/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YHZo3CWRcf5easAHDNLD4wAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/04/13/patch_tuesday_april/
[7] https://www.justice.gov/opa/press-release/file/1386631/download
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YHZo3CWRcf5easAHDNLD4wAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://whitepapers.theregister.com/
Now you know you can blame the FBI if similar things go TITSUP in the future? *
The government knows best and we work for you. In ye olde days, there were book burnings to try to wrest command and control back from the starved of information and advanced intelligence masses to a self chosen almighty vulnerable few.
* Well, of course you can, and why wouldn't you whenever you know they are capable of looking out for you so diligently, and are enabled by approval to be able to act autonomously on your behalf. Quite whether you would agree and accept that as a good thing in their remit is a whole other different matter.
Methinks that sort of little leak is the fatal vital straw that causes the hoovering dams to burst.
FTFY
This is the first time I've ever heard of this type of action by the federal government. I'm not sure why this was done secretly, not even notifying at least the website owners ahead of time.
It would be interesting to hear more on why the FBI thought the action justified: the article seems to imply that it might be under national security purposes?
Don't mind us
Just playing through....
"Don't worry about security, the government will cover for us if we fuck it up"
I wonder how much Microsoft paid the feds for their services here? I don't see any mention of that. In fact, the article comes across like they didn't pay and are effectively using the gubmint as a free security / triage / mitigation tream.
I'll have to talk to some of the small businesses I work with. They'll be thrilled to be able to call the gubmint to have their virus scans done for free. They're always complaining about how I expect to be paid for services like that.
Dangerous precedent.
What next? Did they have a captain cook at the email too? Maybe looking for some incriminating metadata. If you go through those email systems there is a lot of stuff there like drug testing reports, pricing info that you really want to be kept private.