Arab Press

بالشعب و للشعب
Wednesday, Nov 12, 2025

Microsoft warns multiple groups attacking clients' email servers, not just Chinese hackers

Microsoft warns multiple groups attacking clients' email servers, not just Chinese hackers

Researchers fear that cyber criminals could exacerbate an initial hacking campaign attributed to a state-sponsored group in China.

Microsoft has warned that "multiple actors" are attacking its clients' email servers following a global hacking campaign which it last week attributed to a China-based state-sponsored group.

Researchers fear the tools used by the initial state-sponsored attackers to access Microsoft Exchange servers could now be exploited by criminals, with calls growing for President Biden to urgently raise the issue with Beijing.

The Chinese state-sponsored campaign is believed to have indiscriminately compromised tens of thousands of on-premise email servers worldwide with an intention to subsequently target specific victims.

Calls are growing for President Joe Biden to intervene.


Last week government security authorities amplified Microsoft's urgent call for customers running on-premise Exchange servers to apply the patch, and the company is now warning that there are multiple groups taking advantage of unpatched systems.

Microsoft initially warned that the state-sponsored group "primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defence contractors, policy think tanks, and NGOs".

After compromising email servers belonging to these organisations, Microsoft said the attackers created web shells - interfaces which allow them to remotely access the compromised network even after the original vulnerabilities were patched - which is provoking additional concern.

Because the campaign was so broad, not all of the compromised servers are operated by organisations that would typically be of interest to cyber spies

But experts are concerned that if criminals were to piggyback on those spies' access then they could cause significant collateral damage.

Dmitri Alperovitch, the co-founder and former chief technology officer of cyber security firm Crowdstrike, warned that financially-motivated criminals could access these webshells and potentially deploy ransomware.


"Because this campaign is still ongoing - Chinese have webshells on tens of thousands of networks - the response must demand immediate shutdown of those implants to limit damage, not just signal our displeasure with the fact that it had occurred. Needs to happen now," he added.

The UK's National Cyber Security Centre said it is working to establish the extent of the campaign's impact on the country.

One cyber security professional told Sky News their business had seen a number of clients in the UK compromised by the campaign, many of whom they would not have expected to be a typical target for Beijing, suggesting the attackers would have a subsequent triage stage to select specific victims.

The Washington Post reported that the "indiscriminate nature" of the campaign has caused concern among officials, and that the Biden administration was moving to address the incident - although no actions have yet been announced.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
Cristiano Ronaldo Embraces Saudi Arabia’s 2034 World Cup Vision with Key Role
Saudi Arabia’s Execution Campaign Escalates as Crown Prince Readies U.S. Visit
Trump Unveils Middle East Reset: Syria Re-engaged, Saudi Ties Amplified
Saudi Arabia to Build Future Cities Designed with Tourists in Mind, Says Tourism Minister
Saudi Arabia Advances Regulated Stablecoin Plans with Global Crypto Exchange Support
Saudi Arabia Maintains Palestinian State Condition Ahead of Possible Israel Ties
Chinese Steel Exports Surge 41% to Saudi Arabia as Mills Pivot Amid Global Trade Curbs
Saudi Arabia’s Biban Forum 2025 Secures Over US$10 Billion in Deals Amid Global SME Drive
Saudi Arabia Sets Pre-Conditions for Israel Normalisation Ahead of Trump Visit
MrBeast’s ‘Beast Land’ Arrives in Riyadh as Part of Riyadh Season 2025
Cristiano Ronaldo Asserts Saudi Pro League Outperforms Ligue 1 Amid Scoring Feats
AI Researchers Claim Human-Level General Intelligence Is Already Here
Saudi Arabia Pauses Major Stretch of ‘The Line’ Megacity Amid Budget Re-Prioritisation
Saudi Arabia Launches Instant e-Visa Platform for Over 60 Countries
Dick Cheney, Former U.S. Vice President, Dies at 84
Saudi Crown Prince to Visit Trump at White House on November Eighteenth
Trump Predicts Saudi Arabia Will Normalise with Israel Ahead of 18 November Riyadh Visit
Entrepreneurial Momentum in Saudi Arabia Shines at Riyadh Forward 2025 Summit
Saudi Arabia to Host First-Ever International WrestleMania in 2027
Saudi Arabia to Host New ATP Masters Tournament from 2028
Trump Doubts Saudi Demand for Palestinian State Before Israel Normalisation
Viral ‘Sky Stadium’ for Saudi Arabia’s 2034 World Cup Debunked as AI-Generated
Deal Between Saudi Arabia and Israel ‘Virtually Impossible’ This Year, Kingdom Insider Says
Saudi Crown Prince to Visit Washington While Israel Recognition Remains Off-Table
Saudi Arabia Leverages Ultra-Low Power Costs to Drive AI Infrastructure Ambitions
Saudi Arabia Poised to Channel Billions into Syria’s Reconstruction as U.S. Sanctions Linger
Smotrich’s ‘Camels’ Remark Tests Saudi–Israel Normalisation Efforts
Saudi Arabia and Qatar Gain Structural Edge in Asian World Cup Qualification
Israeli Energy Minister Delays $35 Billion Gas Export Agreement with Egypt
Fincantieri and Saudi Arabia Agree to Build Advanced Maritime Ecosystem in Kingdom
Saudi Arabia’s HUMAIN Accelerates AI Ambitions Through Major Partnerships and Infrastructure Push
IOC and Saudi Arabia End Ambitious 12-Year Esports Games Partnership
CSL Seqirus Signs Saudi Arabia Pact to Provide Cell-Based Flu Vaccines and Build Local Production
Qualcomm and Saudi Arabia’s HUMAIN Team Up to Deploy 200 MW AI Infrastructure
Saudi Arabia’s Economy Expands Five Percent in Third Quarter Amid Oil Output Surge
China’s Vice President Han Zheng Meets Saudi Crown Prince as Trade Concerns Loom
US and Qatar Warn EU of Trade and Energy Risks from Tough Climate Regulation
AI and Cybersecurity at Forefront as GITEX Global 2025 Kicks Off in Dubai
EU Deploys New Biometric Entry/Exit System: What Non-EU Travelers Must Know
Ex-Microsoft Engineer Confirms Famous Windows XP Key Was Leaked Corporate License, Not a Hack
Israel and Hamas Agree to First Phase of Trump-Brokered Gaza Truce, Hostages to Be Freed
Syria Holds First Elections Since Fall of Assad
Altman Says GPT-5 Already Outpaces Him, Warns AI Could Automate 40% of Work
Trump Organization Teams with Saudi Developer on $1 Billion Trump Plaza in Jeddah
Archaeologists Recover Statues and Temples from 2,000-Year-Old Sunken City off Alexandria
Colombian President Petro Vows to Mobilize Volunteers for Gaza and Joins List of Fighters
Nvidia and Abu Dhabi’s TII Launch First AI-&-Robotics Lab in the Middle East
UK, Canada, and Australia Officially Recognise Palestine in Historic Shift
Dubai Property Boom Shows Strain as Flippers Get Buyer’s Remorse
JWST Data Brings TRAPPIST-1e Closer to Earth-Like Habitability
×