Cybereason Discovers Global Botnet Campaign Leveraging Microsoft Exchange Vulnerabilities

General News

Summary

The threat actors, who appear to be Russian speakers, are taking advantage of previously disclosed Microsoft Exchange vulnerabilities leveraged in the Hafnium attacks to penetrate networks. While Prometei was first reported on in July 2020, Cybereason assesses that the botnet actually dates back to at least 2016, a year before the now infamous WannaCry and NotPetya malware attacks that affected more than 200 countries and caused billions in damages. And to make matters worse, cryptomining drains valuable network computing power, negatively impacting business operations and the performance and stability of critical servers,” said Assaf Dahan, senior director and head of threat research, Cybereason. • Cybercrime with APT Flavor: Cybereason assesses that the Prometei Botnet operators are financially motivated and intent on generating hefty sums of bitcoin, but is likely not backed by a nation-state. The Cybereason Defense Platform combines the industry’s top-rated detection and response (EDR and XDR), next-gen anti-virus (NGAV), and proactive threat hunting to deliver context-rich analysis of every element of a Malop (malicious operation).

Classifications

industries
Fintech & Banking
applications
Accounting and Taxes

AskAI Classifications

Labels
SaaS Cloud Computing Enterprise Software

Linked Companies

Microsoft
$1B+
Avere Systems
$1M to $5M
Cybereason Inc.
$10M to $25M