Skip to main content

NSA: Russia's Sandworm Hackers Have Hijacked Mail Servers

posted onMay 29, 2020
by l33tdawg
Wired
Credit: Wired

A warning that hackers are exploiting vulnerable email servers doesn't qualify as an unusual event in general. But when that warning comes from the National Security Agency, and the hackers are some of the most dangerous state-sponsored agents in the world, run-of-the-mill email server hacking becomes significantly more alarming.

On Thursday, the NSA issued an advisory that the Russian hacker group known as Sandworm, a unit of the GRU military intelligence agency, has been actively exploiting a known vulnerability in Exim, a commonly used mail transfer agent—an alternative to bigger players like Exchange and Sendmail—running on email servers around the world. The agency warns that Sandworm has been exploiting vulnerable Exim mail servers since at least August 2019, using the hacked servers as an initial infection point on target systems and likely pivoting to other parts of the victim's network. And while the NSA hasn't said who those targets have been, or how many there are, Sandworm's history as one of the most aggressive and destructive hacking organizations in the world makes any new activity from the group worth noting.

"We still consider this to be one of the most, if not the most aggressive and potentially dangerous actor that we track," says John Hultquist, the director of intelligence at FireEye, who also led a team at iSight Partners when that company first discovered and named Sandworm in 2014.

Source

Tags

Security

You May Also Like

Recent News

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th