FortiNDRCloud
SaaS based NDR solution providing 365 days data retention, along with Technical Success Manager
kcheung
Staff
Staff
Article Id 426344
Description

UNC1549, a suspected Iran-linked espionage group, has been seen targeting organizations in the aerospace, aviation, and defense sectors using vulnerabilities in Microsoft Exchange Server.

 

The following software vulnerabilities have been observed in use during the UNC1549 campaigns:

 

CVE-2020-0688 is a remote code execution (RCE) vulnerability in Microsoft Exchange Server which allows an authenticated attacker to run arbitrary code as SYSTEM on the Exchange server.

 

CVE-2021-26855 is a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server which allows an unauthenticated attacker to execute arbitrary commands on the Exchange server.

CVE ID    

CVE-2020-0688
CVE-2021-26855

NDR Cloud Detection Rule

FortiNDR Cloud v25.4a+

Detection Rule Name Category Primary MITRE ID
FortiGuard Outbreak Alert: Microsoft Exchange Server Remote Code Execution - CVE-2020-0688 Attack: Exploitation T1190 - Exploit Public-Facing Application
FortiGuard Outbreak Alert: Microsoft Exchange Server Remote Code Execution - CVE-2021-26855 Attack: Exploitation T1190 - Exploit Public-Facing Application

 

Playbook N/A
Threat Hunting FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for “UNC1549 Critical Infrastructure Espionage Attack” related activities.
IOC source: UNC1549 Critical Infrastructure Espionage Attack | Indicator of Compromise
All IOCs relating to "UNC1549 Critical Infrastructure Espionage Attack" have been added to Threat Intelligence Intel.
Suricata Coverage Customers can create custom investigation/detections using the Suricata signatures below:
2029540 -> ET WEB_SPECIFIC_APPS Possible Attempted Microsoft Exchange RCE (CVE-2020-0688)
Other Fortinet Products

For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to:
UNC1549 Critical Infrastructure Espionage Attack

Contributors