Microsoft Exchange Server Attacks Lockfile Ransomware Uses A Novel Attack Method
Security researchers at Sophos say LockFile has been targeting vulnerable Microsoft Exchange servers by exploiting ProxyShell flaws in the platform. It uses an “intermittent encryption” attack to stay away from security tools. Researchers from Sophos discovered the emerging threat in July, which exploits the ProxyShell vulnerabilities in Microsoft Exchange servers to attack systems. Specifically, LockFile encrypts on every 16 bytes of a file, which means many anti-ransomware software services cannot detect it....