Microsoft Warns Of Stealthy Backdoors Used To Target Exchange Servers
Microsoft has offered insights into how to spot and remove malicious IIS extensions, which aren’t as popular as web shells as a payload for Exchange servers, but are useful to an attacker as they “mostly reside in the same directories as legitimate modules used by target applications, and they follow the same code structure as clean modules,” Microsoft notes. As such, they might not be seen as malicious and identifying the source of an infection can be difficult....