Microsoft says some SharePoint server hackers now using ransomware

file

A cyber-espionage campaign centered on vulnerable versions of Microsoft's MSFT.O server software now involves the deployment of ransomware, Microsoft said in a late Wednesday blog post.

In the post, citing "expanded analysis and threat intelligence," Microsoft said a group it dubs "Storm-2603" is using the vulnerability to seed the ransomware, which typically works by paralyzing victims' networks until a digital currency payment is made.

The disclosure marks a potential escalation in the campaign, which has already hit at least 400 victims, according to Netherlands-based cybersecurity firm Eye Security. Unlike typical state-backed hacker campaigns, which are aimed at stealing data, ransomware can cause widespread disruption depending on where it lands.

The figure of 400 victims represents a sharp rise from the 100 organizations cataloged over the weekend. Eye Security says the figure is likely an undercount.

"There are many more, because not all attack vectors have left artifacts that we could scan for," said Vaisha Bernard, the chief hacker for Eye Security, which was among the first organizations to flag the breaches.

The details of most of the victim organizations have not yet been fully disclosed, but on Wednesday a representative for the National Institutes of Health confirmed that one of the organization's servers had been compromised.

"Additional servers were isolated as a precaution," he said. The news of the compromise was first reported by the Washington Post.

Other outlets said the hacking campaign had breached an even broader range of U.S. agencies. NextGov, citing multiple people familiar with the matter, reported the Department of Homeland Security had been hit, along with more than five to 12 other agencies.

Politico, which cited two U.S. officials, said multiple agencies were believed to have been breached.

DHS' cyberdefense arm, CISA, did not immediately return a message seeking comment on the reports. Microsoft did not immediately return a message seeking further details on the ransomware angle of the hacking or the reported government victims.

The spy campaign began after Microsoft failed to fully patch a security hole in its SharePoint server software, kicking off a scramble to fix the vulnerability when it was discovered.

Microsoft and its tech rival, Google-owner Alphabet GOOGL.O, have both said Chinese hackers are among those taking advantage of the flaw. Beijing has denied the claim.

More from Business

  • H.H. Sheikh Mohammed emphasises UAE's role as global hub for trade

    His Highness Sheikh Mohammed bin Rashid Al Maktoum, Vice President and Prime Minister of the UAE and Ruler of Dubai, has visited the 31st edition of Gulfood, the world’s leading food and beverage sourcing event, marking the largest edition in its history.

  • Ajman to set up rental dispute resolution centre

    A new Rental Dispute Resolution Centre will be established in Ajman to streamline the handling of landlord-tenant disputes and strengthen stability in the real estate sector.

  • H.H. Sheikh Hamdan witnesses expansion agreement for Hewi Dubai

    H.H. Sheikh Hamdan bin Mohammed bin Rashid Al Maktoum, Crown Prince of Dubai, Deputy Prime Minister, Minister of Defence, and Chairman of The Executive Council of Dubai, witnessed the signing of a partnership agreement between Dubai Municipality, the General Construction Company and Binghatti, to develop Hewi Al Barsha and Hewi Muhaisnah.

  • India to slash tariffs on cars to 40% in trade deal with EU

    India plans to slash tariffs on cars imported from the European Union to 40 per cent from as high as 110 per cent, sources said, in the biggest opening yet of the country's vast market as the two sides close in on a free trade pact that could come as early as Tuesday.

Coming Up