Cyber Security News

GhostContainer Malware Hacking Exchange Servers in the Wild Using N-day Vulnerability

A highly sophisticated malware campaign targeting Microsoft Exchange servers in government and high-tech organizations across Asia. 

The malware, dubbed GhostContainer, exploits known N-day vulnerabilities to establish persistent backdoor access to critical infrastructure.

Key Takeaways
1. GhostContainer uses CVE-2020-0688 vulnerability to create persistent backdoors.
2. Three-stage architecture enables web proxy, tunneling, and stealth operations within legitimate Exchange traffic.
3. APT campaign compromised government agencies and tech companies across Asia.

Advanced Backdoor Capabilities and Evasion Techniques

Kaspersky reports that the GhostContainer malware (App_Web_Container_1.dll, SHA256: 87a3aefb5cdf714882eb02051916371fbf04af2eb7a5ddeae4b6b441b2168e36) demonstrates remarkable technical sophistication through its multi-functional backdoor architecture. 

The malware employs a three-class structure consisting of Stub, App_Web_843e75cf5b63, and App_Web_8c9b251fb5b3, each serving distinct operational purposes.

To evade detection, the malware immediately attempts to bypass AMSI (Antimalware Scan Interface) and Windows Event Log by overwriting specific addresses in amsi.dll and ntdll.dll. 

The backdoor utilizes the Exchange server’s ASP.NET validation key, retrieved from machine configuration and hashed using SHA-256 to create a 32-byte AES encryption key for secure command and control communications.

The malware supports fourteen distinct command operations, including shellcode execution, file manipulation, .NET bytecode loading, and HTTP POST requests to multiple URLs concurrently. 

Each command generates XML-formatted responses containing the hardcoded string /wEPDwUKLTcyODc4, which researchers have linked to the open-source ExchangeCmdPy.py exploitation tool.

GhostContainer Leverages Exchange Flaw (CVE-2020-0688)

Analysis reveals that GhostContainer leverages multiple open-source projects, particularly code similarities with ExchangeCmdPy.py, suggesting exploitation of CVE-2020-0688, a deserialization vulnerability in Exchange servers. 

The attack employs a sophisticated virtual page injection mechanism through the App_Web_843e75cf5b63 class, which creates ghost pages using VirtualProvider classes to bypass file system checks.

The malware’s web proxy component, App_Web_8c9b251fb5b3, is based on the Neo-reGeorg tunneling tool and processes requests through custom headers: Qprtfva for proxy forwarding and Dzvvlnwkccf for socket communication. 

This dual-functionality enables both web proxy operations and long-lived TCP tunnel establishment between internal networks and external command infrastructure.

Current telemetry indicates that GhostContainer has successfully compromised at least two high-value targets: a key government agency and a high-tech company, both located in Asia. 

The malware’s design specifically targets Exchange infrastructure within government environments, suggesting a focused APT campaign against critical national infrastructure.

Unlike traditional malware campaigns, GhostContainer operates without establishing direct connections to external C2 infrastructure.

GhostContainer C2 Commands and Functionality

Command IDFunctionality
0Get the system architecture type (e.g., x86 or x64).
1Run received data as shellcode.
2Execute a command line.
3Load .NET byte code in a child thread.
4Send a GET request.
5Download and save a file.
6Save provided raw data to a file.
7Delete a file.
8Read file contents.
9Execute a .NET program with output.
10Invoke the virtual page injector (App_Web_843e75cf5b63).
11Delete files containing “App_Global” in their names.
14Perform HTTP POST requests to multiple URLs concurrently.

Instead, attackers connect to compromised servers from outside networks, concealing control commands within legitimate Exchange web requests. 

The sophisticated nature of the attack, combined with the malware’s ability to function as both a backdoor and network tunnel, indicates the involvement of a highly skilled and professional threat actor with a deep understanding of Exchange systems and web service operations.

GhostContainer Indicators of Compromise (IoC)

Indicator TypeValue
FilenameApp_Web_Container_1.dll
MD501d98380dfb9211251c75c87ddb3c79c

Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -> Try ANY.RUN Now 

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago