Ransomware group is now leveraging backdoors that persist, cybersecurity consulting firm Pondurance says. Microsoft issued emergency patches for four vulnerabilities in certain versions of its on-premises Exchange email servers on March 4. Conti apparently is attacking organizations that mitigated the Exchange flaws first exploited by Chinese attackers but failed to identify and remove the already-installed backdoor access, researchers say. A disgruntled Conti affiliate reportedly has leaked key training material from the group after complaining about the profit split, according to a report.”]
Source: https://www.cuinfosecurity.com/conti-group-takes-advantage-vulnerable-exchange-servers-a-17252

