{"id":463187,"date":"2022-10-05T17:11:09","date_gmt":"2022-10-05T15:11:09","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=463187"},"modified":"2022-10-05T17:16:05","modified_gmt":"2022-10-05T15:16:05","slug":"scammers-selling-bogus-microsoft-exchange-exploits-on-github","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/463187-scammers-selling-bogus-microsoft-exchange-exploits-on-github.html","title":{"rendered":"Scammers selling bogus Microsoft Exchange exploits on GitHub"},"content":{"rendered":"<p>Malicious actors are pretending to be security researchers and selling phoney proof-of-concept ProxyNotShell exploits for recently discovered zero-day flaws in Microsoft Exchange.<\/p>\n<p>According to a Bleeping Computer <strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-microsoft-exchange-proxynotshell-exploits-for-sale-on-github\/\" target=\"_blank\" rel=\"noopener\">report<\/a><\/strong>, a scammer has started creating GitHub repositories through which they are trying to sell fake proof-of-concept exploits for the vulnerabilities.<\/p>\n<p>The flaws \u2014 tracked as CVE-2022-41040 and CVE-2022-41082 \u2014 were <strong><a href=\"https:\/\/mybroadband.co.za\/news\/security\/462649-two-actively-exploited-zero-day-flaws-threaten-microsoft-exchange-servers.html\" target=\"_blank\" rel=\"noopener\">disclosed last week<\/a><\/strong> after the Vietnamese cybersecurity firm GTSC first spotted the vulnerabilities in August 2022.<\/p>\n<p>According to cybersecurity researcher <strong><a href=\"https:\/\/twitter.com\/_JohnHammond\/status\/1575849524169523201?s=20&amp;t=DtQ1C1PPFrP0StG1jHycCQ\" target=\"_blank\" rel=\"noopener\">John Hammond<\/a><\/strong>, who has been tracking the scammers, five now-removed GitHub accounts were attempting to sell the fake exploits.<\/p>\n<p>He noted that a sixth was still active and is impersonating cybersecurity researcher Kevin Beaumont, who has been documenting the flaws and available workarounds.<\/p>\n<p>Bleeping Computer reported that the repositories themselves aren&#8217;t important.<\/p>\n<p>However, the README.md file included in the repositories provides details on what is currently known about the flaws, followed by a sales pitch.<\/p>\n<div id=\"attachment_463189\" style=\"width: 1210px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/10\/Github-repository-README.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-463189\" class=\"size-full wp-image-463189\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/10\/Github-repository-README.jpg\" alt=\"\" width=\"1200\" height=\"369\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/10\/Github-repository-README.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/10\/Github-repository-README-600x185.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/10\/Github-repository-README-800x246.jpg 800w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/10\/Github-repository-README-768x236.jpg 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/a><p id=\"caption-attachment-463189\" class=\"wp-caption-text\">Via: <strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-microsoft-exchange-proxynotshell-exploits-for-sale-on-github\/\" target=\"_blank\" rel=\"noopener\">Bleeping Computer<\/a><\/strong><\/p><\/div>\n<p>&#8220;This means it can go unnoticed by the user and potentially by the security team as well,&#8221; it reads.<\/p>\n<p>&#8220;Such a powerfull [sic] tool should not be fully public, there is strictly only 1 copy available so a REAL researcher can use it: https:\/\/satoshidisk.com\/pay\/xxx.&#8221;<\/p>\n<p>After that, it specifies that readers must not resell or leak the proof-of-concept as that would put them &#8220;at risk of breaking the law&#8221;.<\/p>\n<p>According to GTSC, exploiting the vulnerabilities could help malicious actors access Microsoft Exchange server systems to drop web shells and carry out lateral movements across the compromised network.<\/p>\n<p>&#8220;We detected webshells, mostly obfuscated, being dropped to Exchange servers,&#8221; it said.<\/p>\n<p>&#8220;Using the user-agent, we detected that the attacker uses Antsword, an active Chinese-based open source cross-platform website administration tool that supports web shell management.&#8221;<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/463157-activision-blizzard-hit-by-ddos-attack-on-overwatch-2-launch-day.html\" rel=\"bookmark\">Activision Blizzard hit by DDoS attack on Overwatch 2 launch day<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Scammers pretending to be security researchers are selling fake exploits for recently discovered zero-day flaws in Microsoft Exchange.<\/p>\n","protected":false},"author":341076,"featured_media":463191,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[11253,81707,81777,78704,68902],"class_list":["post-463187","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-github","tag-gtsc","tag-john-hammond","tag-kevin-beaumont","tag-microsoft-exchange"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/463187"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=463187"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/463187\/revisions"}],"predecessor-version":[{"id":463293,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/463187\/revisions\/463293"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/463191"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=463187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=463187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=463187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}