Security News > 2021 > December > Hackers steal Microsoft Exchange credentials using IIS module

Hackers steal Microsoft Exchange credentials using IIS module
2021-12-14 17:16

Threat actors are installing a malicious IIS web server module named 'Owowa' on Microsoft Exchange Outlook Web Access servers to steal credentials and execute commands on the server remotely.

Microsoft Exchange servers are commonly targeted with web shells that allow threat actors to remotely execute commands on a server and are usually the focus of defenders.

Using an IIS module as a backdoor is an excellent way to stay hidden.

Owowa specifically targets OWA applications of Exchange servers and is designed to log the credentials of users that successfully authenticate on the OWA login web page.

"This is an efficient option for attackers to gain a strong foothold in targeted networks by persisting inside an Exchange server."

Exe' or the IIS configuration tool to get a list of all loaded modules on an IIS server.


News URL

https://www.bleepingcomputer.com/news/security/hackers-steal-microsoft-exchange-credentials-using-iis-module/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 701 841 4687 4342 3722 13592