ALL NEWS

Microsoft says a group of cyberattackers tied to China hit its Exchange email servers

Mar 3, 2021, 6:14 AM | Updated: 6:15 am

NEW YORK, NY - MAY 2: The Microsoft logo is illuminated on a wall during a Microsoft launch event t...

NEW YORK, NY - MAY 2: The Microsoft logo is illuminated on a wall during a Microsoft launch event to introduce the new Microsoft Surface laptop and Windows 10 S operating system, May 2, 2017 in New York City. The Windows 10 S operating system is geared toward the education market and is Microsoft's answer to Google's Chrome OS. (Photo by Drew Angerer/Getty Images)

(Photo by Drew Angerer/Getty Images)

    (CNN) — Microsoft says that a sophisticated group of hackers linked to China has exploited its popular email service that allowed them to gain access to computers.

In a blog post Tuesday, the company said that four vulnerabilities in its software allowed hackers to access servers for Microsoft Exchange, “which enabled access to email accounts, and allowed installation of additional malware to facilitate long-term access to victim environments.” The firm added that the online platform for Exchange, the cloud-based version of the service, was not affected.

Microsoft is now urging users to download software patches, or fixes, for the four different vulnerabilities that were found.

The company said that it believes the attacks were carried out by Hafnium, “a group assessed to be state-sponsored and operating out of China.” It did not offer evidence supporting the assessment, but said the “state-sponsored” actor was identified by the Microsoft Threat Intelligence Center based on observed “tactics and procedures.”

“We are sharing this information with our customers and the security community to emphasize the critical nature of these vulnerabilities and the importance of patching all affected systems immediately,” it said.

“This blog also continues our mission to shine a light on malicious actors and elevate awareness of the sophisticated tactics and techniques used to target our customers.”

Hafnium is a network of hackers that “primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks and [non-government organizations],” according to Microsoft.

Though the group is believed to be based in China, it usually strikes using virtual private servers based in the United States, the company said.

Asked about the Microsoft blog post, a spokesperson for China’s Ministry of Foreign Affairs said that the country “firmly opposes and fights all forms of cyber-attacks and thefts in accordance with the law.”

“Connecting cyberattacks directly to the government is a highly sensitive political issue,” Wang Wenbin told reporters at a regular press briefing. “China hopes that relevant media and companies will adopt a professional and responsible attitude. When characterizing cyber incidents, it should be based on sufficient evidence, rather than unprovoked guesses.”

“Exchange Server is primarily used by business customers, and we have no evidence that Hafnium’s activities targeted individual consumers or that these exploits impact other Microsoft products,” Tom Burt, Microsoft’s corporate vice president, customer security and trust, added in a separate blog post.

This isn’t Microsoft’s first tangle with Hafnium. The tech giant has previously — on separate, unrelated occasions — observed the group “interacting with victim” users of Office 365, it said.

But “this is the first time we’re discussing its activity,” wrote Burt.

“While they are often unsuccessful in compromising customer accounts, this reconnaissance activity helps the adversary identify more details about their targets’ environments,” the company said.

— CNN’s Beijing bureau contributed to this report.

The-CNN-Wire
™ & © 2021 Cable News Network, Inc., a WarnerMedia Company. All rights reserved.

We want to hear from you.

Have a story idea or tip? Send it to the KSL NewsRadio team here.

All News

FILE - The Utah State Board of Education is pictured in Salt Lake City. (Kristin Murphy/Deseret New...

Eric Cabrera

Is chronic absenteeism in students as bad as we think it is?

Chronic absenteeism in students has been a rising issue in schools, but is it as bad as we've heard it is?

53 minutes ago

Costco and its low-cost health care partner Sesame have launched a weight loss program that include...

Curt Gresseth

Women on birth control and weight-loss meds are becoming pregnant

Some women on birth control who are also taking weight-loss medications like Ozempic are becoming pregnant.

2 hours ago

Planting tomatoes is like building a house, meaning you have to start with a good foundation. In th...

Michelle Lee

A beginner-friendly guide to planting tomatoes

There’s no doubt that tomatoes are extremely popular among gardeners in Utah. Read on to get some tips for planting tomatoes from our local tomato expert Andy Stevenson with J&J Nursery and Garden Center.

3 hours ago

signs during gop convention...

Bridger Beal-Cvetko, KSL.com

Here’s what’s at stake at GOP, Democratic nominating conventions this weekend

Saturday will mark the end of the road for some candidates' election hopes as Republican and Democratic delegates convene to select party nominees.

3 hours ago

ksl movie show host steve salles stands next to humane movie poster...

Steve Salles

KSL Movie Show review: ‘Humane’ is smart, and just horrifying enough

In this KSL Movie Show review, host Steve Salles explores "Humane," which presents a world in desperate need of less people.

4 hours ago

police tape pictured, two men were arrested in west jordan over cockfighting...

Pat Reavy, KSL.com

2 arrested in cockfighting case that began with a teen at school with a gun

Two men accused of engaging in game fowl fighting, commonly referred to as cockfighting, were arrested Thursday in West Jordan.

4 hours ago

Sponsored Articles

a doctor putting her hand on the chest of her patient...

Intermountain Health

Intermountain nurse-midwives launch new gynecology access clinic

An access clinic launched by Intermountain nurse-midwives provides women with comprehensive gynecology care.

Young couple hugging while a realtor in a suit hands them keys in a new home...

Utah Association of Realtors

Buying a home this spring? Avoid these 5 costly pitfalls

By avoiding these pitfalls when buying a home this spring, you can ensure your investment will be long-lasting and secure.

a person dressed up as a nordic viking in a dragon boat resembling the bear lake monster...

Bear Lake Convention and Visitors Bureau

The Legend of the Bear Lake Monster

The Bear Lake monster has captivated people in the region for centuries, with tales that range from the believable to the bizarre.

...

Live Nation Concerts

All the artists coming to Utah First Credit Union Amphitheatre (formerly USANA Amp) this summer

Summer concerts are more than just entertainment; they’re a celebration of life, love, and connection.

Mother and cute toddler child in a little fancy wooden cottage, reading a book, drinking tea and en...

Visit Bear Lake

How to find the best winter lodging in Bear Lake, Utah

Winter lodging in Bear Lake can be more limited than in the summer, but with some careful planning you can easily book your next winter trip.

Happy family in winter clothing at the ski resort, winter time, watching at mountains in front of t...

Visit Bear Lake

Ski more for less: Affordable ski resorts near Bear Lake, Utah

Plan your perfect ski getaway in Bear Lake this winter, with pristine slopes, affordable tickets, and breathtaking scenery.

Microsoft says a group of cyberattackers tied to China hit its Exchange email servers