Microsoft said Russian state-backed threat actor Forest Blizzard (also tracked as APT28 or STRONTIUM) actively exploited CVE-2023-23397, a critical Outlook for Windows elevation-of-privilege flaw that can leak a victim’s Net-NTLMv2 hash through a specially crafted reminder message without user interaction. The stolen hash can then be used in NTLM relay attacks against Exchange, allowing attackers to access Exchange-hosted mailboxes, move laterally, and establish persistence. Microsoft said exploitation dated back to at least April 2022 and linked the activity to the GRU-associated actor previously tied by U.S. and U.K. authorities to Unit 26165.
Reporting from Microsoft and other security firms tied the campaign to broader Russian espionage operations targeting government, military, energy, transportation, research, and other strategic organizations, with Unit 42 saying at least 30 organizations in 14 countries were affected over roughly 20 months, many in NATO states. Investigators observed attackers abusing Exchange Web Services and modifying mailbox folder permissions to retain unauthorized access to mailbox contents, a technique also highlighted by Polish authorities. Microsoft urged defenders to patch Outlook, apply Exchange security updates, block outbound SMB on TCP 445, and reduce or disable NTLM exposure; it also noted that Exchange Online and updated Exchange Server builds can strip the malicious PidLidReminderFileParameter used in the attack chain.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By December 2023, Microsoft, ANSSI, Recorded Future, Proofpoint, and Palo Alto Networks Unit 42 had linked the CVE-2023-23397 activity to broader Russian state-sponsored campaigns targeting government, military, energy, transportation, research, and other strategic organizations. Unit 42 said the campaign affected at least 30 organizations in 14 countries over roughly 20 months, mostly in NATO member states.
On March 24, 2023, Microsoft publicly detailed active exploitation of CVE-2023-23397, attributed the activity to Forest Blizzard/STRONTIUM, and released hunting guidance, indicators, and mitigation recommendations. Microsoft said the actor used the flaw to access Exchange environments, move laterally, and abuse NTLM relay and Exchange Web Services.
Microsoft patched the critical Outlook for Windows elevation-of-privilege vulnerability CVE-2023-23397 in March 2023. The update prevents Outlook from honoring untrusted remote paths used in the attack chain.
During the exploitation campaign, Forest Blizzard used stolen credentials and Exchange access to modify mailbox folder permissions and maintain persistent unauthorized access to mailbox contents. Polish authorities later highlighted this technique as part of the activity.
Microsoft said evidence of exploitation of the Outlook vulnerability CVE-2023-23397 dates back to April 2022. The flaw allowed specially crafted reminder messages to leak Net-NTLMv2 hashes without user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcetechtarget.com
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.