New 'SessionManager'? Backdoor Targeting Microsoft Exchange Servers Worldwide

New 'SessionManager' Backdoor Targeting Microsoft Exchange Servers Worldwide

New malware has been identified by Kaspersky security experts that targets Microsoft Exchange servers that are used by numerous organizations globally.

The backdoor, known as "SessionManager," allows threat actors to maintain "persistent, update-resistant and very stealth access to the IT infrastructure of a targeted enterprise," according to the company, which discovered it in early 2022.

Once spread, SessionManager, in the opinion of Kaspersky, would allow a wide range of malicious activities, from email collection to total control over the infrastructure of the victim.

According to the security experts' findings, SessionManager's threat actors (TA) first began working in late March 2021.

34 servers from 24 firms in Africa, South Asia, Europe, and the Middle East would have been affected, according to Kaspersky, with the majority of them still being infected as of this writing.

要查看或添加评论,请登录

Luckmore Katiyo的更多文章

社区洞察

其他会员也浏览了