Unidentified threat actors are exploiting vulnerabilities in Microsoft Exchange servers to inject JavaScript keylogger malware into login pages, harvesting user credentials. These attacks have affected 65 victims across 26 countries, including government, banking, and educational institutions. #ProxyShell #ProxyLogon
Keypoints
- Threat actors target publicly exposed Microsoft Exchange servers to deploy malicious keylogger scripts.
- The keylogger variants either store data locally or send it immediately to external servers, evading detection.
- The attacks exploit several known vulnerabilities, including ProxyShell and ProxyLogon flaws, across multiple versions of Exchange Server.
- Victims include government agencies, banks, IT companies, and educational institutions worldwide.
- Malicious code injection into login pages allows long-term undetected credential harvesting via legitimate authentication processes.
Read More: https://thehackernews.com/2025/06/hackers-target-65-microsoft-exchange.html