Blog | G5 Cyber Security

Microsoft Exchange ProxyShell exploits used to deploy Babuk ransomware

A new threat actor is hacking Microsoft Exchange servers and breaching corporate networks using the ProxyShell vulnerability to deploy the Babuk Ransomware. The ProxyShell attacks against vulnerable Microsoft Exchange server started several months ago, with LockFile and Conti being among the first ransomware groups to exploit them. The ransom note used in these attacks asks for a low $10,000 in Monero, but it is likely not conducted by the original Babuk operation, who demanded far larger ransom in Bitcoin. Most of Tortilla’s targets are U.S.-based.”]

Source: https://www.bleepingcomputer.com/news/security/microsoft-exchange-proxyshell-exploits-used-to-deploy-babuk-ransomware/

Exit mobile version