Vietnam.vn - Nền tảng quảng bá Việt Nam

Malware Hidden in Microsoft Exchange: Sophisticated Cyber ​​Espionage Discovered

(NLDO) - Kaspersky's Global Research and Analysis Team has just discovered GhostContainer - a new, sophisticated, never-before-seen backdoor malware.

Người Lao ĐộngNgười Lao Động24/07/2025

According to the Global Research and Analysis Team (GReAT), the GhostContainer malware was installed in systems using Microsoft Exchange, as part of a long-term, advanced persistent threat (APT) campaign targeting key organizations in the Asia region, including major technology companies.

Mã độc ẩn mình trong Microsoft Exchange: Phát hiện gián điệp mạng tinh vi- Ảnh 1.

GhostContainer, hidden in a file named App_Web_Container_1.dll, is actually a multi-purpose backdoor. It is capable of extending its functionality by loading additional remote modules and is based on a variety of open source tools. The malware disguises itself as a legitimate component of the host system, using sophisticated evasion techniques to bypass security software and monitoring systems.

Once in the system, GhostContainer allows attackers to take control of Exchange servers. It can act as a proxy or an encrypted tunnel, allowing them to penetrate deeper into the internal network or steal sensitive data without being detected. These actions have led experts to suspect that the campaign is serving cyber espionage purposes.

Sergey Lozhkin, Head of Kaspersky’s GReAT Asia Pacific and Middle East Africa team, said that the group behind GhostContainer is very knowledgeable about the Exchange and IIS server environments. They use open source code to develop sophisticated attack tools while avoiding obvious traces, making it very difficult to trace the origin.

It is currently unclear which group is behind this campaign, as the malware uses code from multiple open source projects – meaning it is likely to be widely used by various cybercriminal groups around the world. Notably, according to statistics, by the end of 2024, approximately 14,000 malware packages were detected in open source projects, an increase of 48% compared to the end of 2023 – showing that security risks from open source are becoming increasingly serious.

To reduce the risk of falling victim to targeted cyberattacks, businesses should equip their security operations teams with access to up-to-date threat intelligence sources, according to Kaspersky.

Upskilling cybersecurity teams is essential to increase their ability to detect and respond to sophisticated attacks. Businesses should also deploy endpoint detection and troubleshooting solutions, combined with network-level monitoring and protection tools.

Additionally, since many attacks start with phishing emails or other forms of psychological deception, organizations need to regularly provide security awareness training to employees. A coordinated investment in technology, people, and processes is key to helping businesses strengthen their defenses against increasingly complex threats.


Source: https://nld.com.vn/ma-doc-an-minh-trong-microsoft-exchange-phat-hien-gian-diep-mang-tinh-vi-196250724165422125.htm


Comment (0)

No data
No data

Same tag

Same category

Autumn morning by Hoan Kiem Lake, Hanoi people greet each other with eyes and smiles.
High-rise buildings in Ho Chi Minh City are shrouded in fog.
Water lilies in flood season
'Fairyland' in Da Nang fascinates people, ranked in the top 20 most beautiful villages in the world

Same author

Heritage

Figure

Enterprise

Cold wind 'touches the streets', Hanoians invite each other to check-in at the beginning of the season

News

Political System

Destination

Product