HT TECH wants to start sending you push notifications. Click allow to subscribe

Microsoft probes clue that hackers cracked Taiwan research

Microsoft is investigating whether hackers who attacked its email system exploited the findings of Taiwanese researchers who were the first to alert the software company to the vulnerabilities, according to a person familiar with the investigation.

By: BLOOMBERG
Updated on: Aug 21 2022, 15:49 IST
FILE PHOTO: A Microsoft logo is seen in Los Angeles, California U.S. November 7. (REUTERS)
FILE PHOTO: A Microsoft logo is seen in Los Angeles, California U.S. November 7. (REUTERS)

Microsoft is investigating whether hackers who attacked its email system exploited the findings of Taiwanese researchers who were the first to alert the software company to the vulnerabilities, according to a person familiar with the investigation.

DEVCORE, a small firm based in Taipei City that specializes in discovering computer security flaws, in December said it found bugs affecting Microsoft’s widely used Exchange business email software. Then in late February, Microsoft notified DEVCORE that it was close to releasing security patches to fix the problem.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
27% OFF
Microsoft Surface Studio A1Y 00022
  • Platinum Silver
  • 16 GB LPDDR4X RAM
  • 512 GB SSD
₹179,990₹245,900
Buy now
7% OFF
Microsoft Surface Pro 8 8PV 00029
  • Graphite Black
  • 16 GB DDR4 RAM
  • 256 GB SSD
₹139,999₹149,999
Buy now
47% OFF
Microsoft Surface 4 5UI 00049
  • Platinum Silver
  • 8 GB DDR4 RAM
  • 256 GB SSD
₹98,000₹186,500
Buy now
28% OFF
Microsoft Surface Pro 7 M1866 VDH 00013
  • Platinum
  • 4 GB LPDDR4X RAM
  • 128 GB SSD
₹74,000₹102,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
21% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,749₹24,990
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

In the days after Microsoft disclosed its still-secret patch to DEVCORE, attackers escalated their malicious activity on networks using Exchange servers connected to the internet, according to researchers at Palo Alto Networks Inc.

Microsoft is exploring if intelligence it shared with partners may have somehow triggered the attack, Bloomberg News reported. The company has focused part of its investigation on understanding if DEVCORE may have been compromised, or in some way tipped off attackers that the patch was in the pipeline, valuable intelligence for hackers seeking to time their attack to maximize its impact, according to the person, who asked not to be identified because details of the probe haven’t been publicly released.

Also read: Microsoft says ransom-seeking hackers taking advantage of server flaws

A Microsoft spokesperson confirmed the investigation, but didn’t comment on whether DEVCORE’s role is under scrutiny.

“We are looking at what might have caused the spike of malicious activity and have not yet drawn any conclusions,” said the spokesperson. “We have seen no indications of a leak from Microsoft related to this attack.”

Bowen Hsu, senior project manager at DEVCORE, said in an email that the company has found no signs that its security was breached.

“DEVCORE immediately launched an internal investigation on March 3rd to verify whether the team has been hacked or any information has been leaked from our end,” Hsu said. “We had a thorough investigation among all the personal computers/devices owned by our employees, as well as our internal infrastructure and systems; there was no sign that any of those devices and our systems have been hacked. Also, we have investigated our internal system and found no unusual login attempts or file access.”

Some of the flaws have since been exploited by suspected Chinese state-sponsored hackers and other unknown cyber-espionage groups, who have breached more than 60,000 servers worldwide in one of the largest and most damaging hacks in recent memory. In some cases, victims who still haven’t installed the Microsoft patch, have been targeted with ransomware.

According to DEVCORE, its researchers discovered two security flaws in exchange servers from Dec. 10 to Dec. 30, and used them to create a proof of concept “exploit” that could be deployed to break into the servers and secretly access emails. The company disclosed its discovery to Microsoft on Jan 5., and Microsoft began working on a patch to fix the problem.

But on Jan. 3 -- two days before the disclosure to Microsoft -- hackers began using one of the same security flaws discovered by DEVCORE to gain access to exchange servers and steal emails, according to researchers at the Virginia-based cybersecurity firm Volexity.

In late February, Microsoft notified DEVCORE that it was nearly ready to release the security patches. The same day, there was an increase in hacker activity, according to security researchers at Palo Alto Networks Inc. The Palo Alto Networks researchers reviewed code of the malware the hackers were using to breach the Microsoft Exchange servers and made a curious discovery. Some strains of the malware contained the password, “orange.”

Read more: Microsoft says China-linked group targeting Exchange email servers

The researcher at DEVCORE who first found the security flaws in the exchange servers is goes by the name Orange Tsai. On Twitter, Tsai pointed out that the exploit used during the February attacks “looks the same” as the one he created as a proof of concept and that DEVCORE reported to Microsoft. He said he had hard-coded the password “orange” into the malware.

The discoveries by Palo Alto Networks and Volexity alarmed researchers at DEVCORE, because the findings indicate that DEVCORE’s research had been surreptitiously obtained by the hackers, according to a person familiar with the matter.

Matthieu Faou, a malware researcher at European cybersecurity company ESET, said the hackers may have independently found the same vulnerabilities in Microsoft Exchange. The other most likely scenario, he added, was that the hackers “somehow obtained the information from DEVCORE or from a Microsoft partner.”

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 14 Mar, 16:03 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,990₹89,900
Buy now
36% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹18,699₹28,999
Buy now
31% OFF
Samsung Galaxy Tab A7 Lite
  • Silver
  • 3 GB RAM
  • 32 GB Storage
₹9,990₹14,500
Buy now
15% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹96,421₹113,798
Buy now
37% OFF
Wishtel IRA T811
  • 4 GB RAM
  • 64 GB Storage
₹11,999₹18,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
27% OFF
Asus ROG Strix G15 G513QM HF318TS Laptop
  • Eclipse Grey
  • 16 GB RAM
  • 1 TB SSD
₹84,990₹115,990
Buy now
39% OFF
Asus TUF Gaming F15 FX506HF HN026W Laptop
  • Black
  • 8 GB RAM
  • 1 TB SSD
₹55,600₹90,990
Buy now
23% OFF
Asus ROG Strix SCAR II GL504GV ES019T Laptop
  • Gun Metal
  • 16 GB RAM
  • 1 TB HDD
₹199,990₹259,990
Buy now
NEXT ARTICLE BEGINS