Tech

Ransomware gangs hijack 7,000 Exchange servers first hit by Chinese hackers

Ransomware gangs hijack 7,000 Exchange servers first hit by Chinese hackers

Enlarge (credit: Getty Images)

Now organizations using Microsoft Exchange have a new security headache: never-before seen ransomware that’s being installed on thousands of servers that were already infected by state-sponsored hackers in China.

Microsoft reported the new family of ransomware deployment late Thursday, saying that it was being deployed after the initial compromise of servers. Microsoft’s name for the new family is Ransom:Win32/DoejoCrypt.A. The more common name is DearCry.

Piggybacking off Hafnium

Security firm Kryptos Logic said Friday afternoon that it has detected close to 7,000 compromised Exchange servers that are being infected with ransomware. Kryptos Logic security researcher Marcus Hutchins told Ars that the ransomware is DearCry.

Read 10 remaining paragraphs | Comments