ALL NEWS

Microsoft says a group of cyberattackers tied to China hit its Exchange email servers

Mar 3, 2021, 6:14 AM | Updated: 6:15 am

NEW YORK, NY - MAY 2: The Microsoft logo is illuminated on a wall during a Microsoft launch event t...

NEW YORK, NY - MAY 2: The Microsoft logo is illuminated on a wall during a Microsoft launch event to introduce the new Microsoft Surface laptop and Windows 10 S operating system, May 2, 2017 in New York City. The Windows 10 S operating system is geared toward the education market and is Microsoft's answer to Google's Chrome OS. (Photo by Drew Angerer/Getty Images)

(Photo by Drew Angerer/Getty Images)

    (CNN) — Microsoft says that a sophisticated group of hackers linked to China has exploited its popular email service that allowed them to gain access to computers.

In a blog post Tuesday, the company said that four vulnerabilities in its software allowed hackers to access servers for Microsoft Exchange, “which enabled access to email accounts, and allowed installation of additional malware to facilitate long-term access to victim environments.” The firm added that the online platform for Exchange, the cloud-based version of the service, was not affected.

Microsoft is now urging users to download software patches, or fixes, for the four different vulnerabilities that were found.

The company said that it believes the attacks were carried out by Hafnium, “a group assessed to be state-sponsored and operating out of China.” It did not offer evidence supporting the assessment, but said the “state-sponsored” actor was identified by the Microsoft Threat Intelligence Center based on observed “tactics and procedures.”

“We are sharing this information with our customers and the security community to emphasize the critical nature of these vulnerabilities and the importance of patching all affected systems immediately,” it said.

“This blog also continues our mission to shine a light on malicious actors and elevate awareness of the sophisticated tactics and techniques used to target our customers.”

Hafnium is a network of hackers that “primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks and [non-government organizations],” according to Microsoft.

Though the group is believed to be based in China, it usually strikes using virtual private servers based in the United States, the company said.

Asked about the Microsoft blog post, a spokesperson for China’s Ministry of Foreign Affairs said that the country “firmly opposes and fights all forms of cyber-attacks and thefts in accordance with the law.”

“Connecting cyberattacks directly to the government is a highly sensitive political issue,” Wang Wenbin told reporters at a regular press briefing. “China hopes that relevant media and companies will adopt a professional and responsible attitude. When characterizing cyber incidents, it should be based on sufficient evidence, rather than unprovoked guesses.”

“Exchange Server is primarily used by business customers, and we have no evidence that Hafnium’s activities targeted individual consumers or that these exploits impact other Microsoft products,” Tom Burt, Microsoft’s corporate vice president, customer security and trust, added in a separate blog post.

This isn’t Microsoft’s first tangle with Hafnium. The tech giant has previously — on separate, unrelated occasions — observed the group “interacting with victim” users of Office 365, it said.

But “this is the first time we’re discussing its activity,” wrote Burt.

“While they are often unsuccessful in compromising customer accounts, this reconnaissance activity helps the adversary identify more details about their targets’ environments,” the company said.

— CNN’s Beijing bureau contributed to this report.

The-CNN-Wire
™ & © 2021 Cable News Network, Inc., a WarnerMedia Company. All rights reserved.

We want to hear from you.

Have a story idea or tip? Send it to the KSL NewsRadio team here.

All News

LAYTON, Utah -- A mother and her 2 children were pinned under a vehicle after the driver was "blind...

Derrick Jones

Mom and 2 children pinned under a car in Layton

LAYTON, Utah — A mother and her two children were hit be a car as they were leaving a daycare at the Layton Christian Academy on Tuesday. The driver of the vehicle says that they were “blinded by the sun” and was not able to see the pedestrians.  After seeing what had happened, a pastor […]

2 hours ago

Image of an Alaska Air flight taking off from Los Angeles International Airport. The FAA convened a...

Cheri Mossburg and Jason Kravarik, CNN

Off-duty pilot accused of attempting to shut off plane engines mid-flight indicted on 84 counts

(CNN) — Joseph Emerson, the Alaska Airlines pilot who allegedly attempted to shut off the engines of a passenger plane mid-flight in October, was indicted on 84 counts in an Oregon court Tuesday. The grand jury indicted Emerson on one count of endangering aircraft in the first degree and 83 counts of recklessly endangering another […]

3 hours ago

Christmas tip...

Curt Gresseth

If you tip more during Christmas, are you feeling generous or pressured?

Most American say they will tip more, or the same amount as last year, during this Christmas season.

4 hours ago

Image of an Alaska Air flight taking off from Los Angeles International Airport. The FAA convened a...

Pete Muntean, CNN

FAA announces new pilot mental health committee

The issue of pilot mental health surfaced again in October when an off-duty pilot was charged with trying to crash an Alaska Airlines flight.

5 hours ago

Seventy percent of Gen Z looks to TikTok for career advice....

Derrick Jones

TikTok, the Gen Z source for career and salary advice

A whopping 70% of Gen Z uses TikTok for career guidance, with 20% considering it their primary source of such advice.

5 hours ago

christmas presents...

Eric Cabrera

Veterans gift shop provides free presents to veterans in need

The veterans gift shop wrapped up its 80th year at the VA Medical Center in Salt Lake City this week.

6 hours ago

Sponsored Articles

front of the Butch Cassidy museum with a man in a cowboy hat standing in the doorway...

Bear Lake Convention and Visitors Bureau

Looking Back: The History of Bear Lake

The history of Bear Lake is full of fascinating stories. At over 250,000 years old, the lake has seen generations of people visit its shores.

silhouette of a family looking over a lake with a bird in the top corner flying...

Bear Lake Convention and Visitors Bureau

8 Fun Activities To Do in Bear Lake Without Getting in the Water

Bear Lake offers plenty of activities for the whole family to enjoy without having to get in the water. Catch 8 of our favorite activities.

Wellsville Mountains in the spring with a pond in the foreground...

Wasatch Property Management

Advantages of Renting Over Owning a Home

Renting allows you to enjoy luxury amenities and low maintenance without the long-term commitment and responsibilities of owning a home.

Clouds over a red rock vista in Hurricane, Utah...

Wasatch Property Management

Why Southern Utah is a Retirement Paradise

Retirement in southern Utah offers plenty of cultural and recreational opportunities. Find out all that this region has to offer.

Human hand holding a protest banner stop vaping message over a crowded street background....

Prosperous Utah Communities

Utah’s Battle to Protect Youth from Vaping Epidemic Faces New Threat as Proposed Rule Threatens Progress

Utah's strict standards of nicotine levels in vaping products are at risk, increasing health hazards associated with use. Read more about how you can advocate for a better future for Utah's youth.

Aerial photo of Bear Lake shoreline with canopies and people camped out on the beach...

Visit Bear Lake

Last-Minute Summer Vacation Planning? Check Out Bear Lake!

Bear Lake is the perfect getaway if you are last-minute summer vacation planning. Enjoy activities with your whole family at this iconic lake.

Microsoft says a group of cyberattackers tied to China hit its Exchange email servers