Microsoft Exchange email hijacking tool is released online

Ένα εργαλείο για hijacking λογαριασμών ηλεκτρονικού ταχυδρομείου του Microsoft used by the OilRig team was leaked online.

The utility is called Jason and is not currently detected by virus protection machines in VirusTotal.

hijacking

The hijacking tool was made available a few hours ago through their channel , και η δημοσίευση αναφέρει ότι χρησιμοποιείται από την κυβέρνηση του Ιράν “για την προσβολή ηλεκτρονικών μηνυμάτων και την κλοπή πληροφοριών”.

The Jason hijacking tool works by trying various codes s until he finds the right one. The brute-force activity is supported by a list of sample passwords and four text files containing numeric patterns.

Omri Segev Moyal, co-founder and vice president of research at Minerva Labs, analyzed the tool Jason, and states that "it seems to be a relatively simple brute-force program against online messaging services".

VirusTotal analysis reveals that the utility was created in 2015. So far it seems to bypass all the detection mechanisms available by VirusTotal.

The OilRig group, also known as APT34 and HelixKitten, is a group affiliated with the Iranian government. Using the nickname Lab Dookhtegan, someone started leaking information about OilRig on March 26, the tools they used in business and various contact information for group members purportedly working for Iran's Ministry of Intelligence and Security (MOIS).

_______________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).