{"id":47863,"date":"2022-02-22T16:03:27","date_gmt":"2022-02-22T08:03:27","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=47863"},"modified":"2022-02-22T16:03:29","modified_gmt":"2022-02-22T08:03:29","slug":"sophos-uncovers-squirrelwaffle-malware-financial-fraud-attacks-using-the-same-vulnerable-exchange-server","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/02\/22\/sophos-uncovers-squirrelwaffle-malware-financial-fraud-attacks-using-the-same-vulnerable-exchange-server\/","title":{"rendered":"Sophos uncovers Squirrelwaffle malware, financial fraud attacks using the same vulnerable Exchange server"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Sophos, a global leader in next-generation cybersecurity, published <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/02\/15\/vulnerable-exchange-server-hit-by-squirrelwaffle-and-financial-fraud\/\">research<\/a> detailing an incident when the Squirrelwaffle malware loader was used in conjunction with the <a href=\"https:\/\/news.sophos.com\/en-us\/2021\/03\/05\/hafnium-advice-about-the-new-nation-state-attack\/\">ProxyLogon<\/a> and <a href=\"https:\/\/news.sophos.com\/en-us\/2021\/08\/23\/proxyshell-vulnerabilities-in-microsoft-exchange-what-to-do\/\">ProxyShell<\/a> exploits to target an unpatched Microsoft Exchange server and mass distribute Squirrelwaffle to internal and external recipients by inserting malicious replies onto employees\u2019 existing email threads.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The researchers discovered that while the malicious spam campaign was being implemented, the same vulnerable server was used for a financial fraud attack with knowledge extracted from a stolen email thread and \u201ctypo-squatting\u201d to convince an employee to redirect a legitimate customer transaction to the attackers. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The fraud almost succeeded. The transfer of funds to the malicious recipient was authorized, but luckily a bank became suspicious and prevented the transaction from going through.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Matthew Everts, an analyst at Sophos Rapid Response and one of the researchers, said: \u201cIn a typical Squirrelwaffle attack leveraging a vulnerable Exchange server, the attack ends when defenders detect and remediate the breach by patching the vulnerabilities, removing the attacker\u2019s ability to send emails through the server. However, in the incident investigated by <a href=\"https:\/\/www.sophos.com\/en-us\/products\/managed-threat-response\/rapid-response\">Sophos Rapid Response<\/a>, such remediation wouldn\u2019t have stopped the financial fraud attack because the attackers had exported an email thread about customer payments from the victim\u2019s Exchange server. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;It is a good reminder that patching alone isn\u2019t always enough protection. For example, in the case of vulnerable Exchange servers, you need to check that the attackers haven\u2019t left behind a web shell to maintain access. When it comes to sophisticated social engineering attacks such as those used in email thread hijacking, educating employees about what to look out for and how to report it is critical for detection.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Squirrelwaffle Incident Guide&nbsp;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alongside the new research, Sophos has published a <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/02\/15\/rapid-response-the-squirrelwaffle-incident-guide\/\">Squirrelwaffle Incident Guide<\/a> that provides step-by-step guidance on investigating, analyzing, and responding to incidents involving this increasingly popular malware loader, which is distributed as a malicious office document in spam campaigns and provides attackers with an initial foothold in a victim\u2019s environment and a channel to deliver and infect systems with other malware.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The researchers discovered that while the malicious spam campaign was being implemented, the same vulnerable server was used for a financial fraud attack with knowledge extracted from a stolen email thread and \u201ctypo-squatting\u201d to convince an employee to redirect a legitimate customer transaction to the attackers.<\/p>\n","protected":false},"author":6,"featured_media":46775,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,2103,206],"class_list":["post-47863","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-security-breach","tag-sophos"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/47863","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=47863"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/47863\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/46775"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=47863"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=47863"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=47863"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}