Cybersecurity, Privacy, & AI

Trending Now
Agriculture Department Kicks Off $300M Palantir Deal on IT, National Security Work • Vercel Attack Fallout Expands to More Customers and Third-Party Systems • Seeing the Cyber in Economic Statecraft • Responding to a Data Breach: How to Preserve the Attorney-Client Privilege • NIST Cyber Center to Launch OT ‘Visibility’ Project

FBI Removes Malware from Private Sector MS Exchange Servers

The Art of Pics | Shutterstock

The Justice Department has revealed that the FBI executed a court-authorized cyber operation to remove malicious web shell software from hundreds of privately owned compromised Microsoft Exchange servers in the United States. The fix was executed by issuing a command through that backdoor to the server, disabling the malware.

This is the first time that something like this is known to have been done, without the prior knowledge of the servers’ owners and operators; the FBI has subsequently attempted to notify them. “Because the web shells the FBI removed each had a unique file path and name, they may have been more challenging for individual server owners to detect and eliminate than other web shells,” DOJ explained.

Industry reaction has raised numerous concerns, including the precedent this sets for government intervention, whether the government has the legal authority to take such action, and the implications of the fact that the attackers had successfully covered their tracks well enough to evade detection in so many systems.

Sources:

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.