Close Menu
  • Home
  • Lifestyle
  • Tech
  • Travel
  • Review
  • About
  • Contact
What's Hot

Discover the Latest Must-Visit Shops at SM Malls in the East Metro

May 20, 2026

Delinquent Society Turns Hustle Into Anthem With “Kuha Bag”

May 20, 2026

TGP Franchisees Highlight Purpose-Driven Entrepreneurship Through Stories of Service and Community Impact

May 20, 2026
Facebook X (Twitter) Instagram
Manila Republic
  • Home
  • Lifestyle
  • Tech
  • Travel
  • Review
  • About
  • Contact
Manila Republic
Home»Tech»GhostContainer discovered: Kaspersky identifies a new backdoor targeting Microsoft Exchange servers 
Tech

GhostContainer discovered: Kaspersky identifies a new backdoor targeting Microsoft Exchange servers 

GabrielBy GabrielJuly 25, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Kaspersky’s Global Research and Analysis Team (GReAT) has uncovered a new backdoor based on open-source tools, dubbed GhostContainer. The previously unknown highly customized malware was discovered during an incident response (IR) case, targeting Exchange infrastructure within government environments. The malware may be part of an advanced persistent threat (APT) campaign targeting high-value entities in Asia, including high-tech companies.

The file detected by Kaspersky as App_Web_Container_1.dll turned out to be a sophisticated, multi-functional backdoor that leverages several open-source projects and can be dynamically extended with arbitrary functionality through additional module downloads. 

Once loaded, it provides attackers with full control over the Exchange server, enabling a wide range of malicious activities. To avoid detection by security solutions, it uses several evasion techniques and presents itself as a legitimate server component to blend in with normal operations. In addition, it can act as a proxy or tunnel, potentially exposing the internal network to external threats or facilitating the exfiltration of sensitive data from internal systems. Therefore, сyber espionage is suspected to be the aim of the campaign.

“Our in-depth analysis revealed that the attackers are highly skilled at exploiting Exchange systems and leveraging various open-source projects related to infiltrating IIS and Exchange environments, as well as creating and enhancing sophisticated espionage tools based on publicly available code. We will continue monitoring their activity, along with the scope and scale of these attacks, to gain a better understanding of the threat landscape.” comments Sergey Lozhkin, Head of GReAT, APAC & META.

At this time, it is not possible to attribute GhostContainer to any known threat actor group, as the attackers have not exposed any infrastructure. The malware incorporates code from several publicly accessible open-source projects, which could be leveraged by hackers or APT groups worldwide. Notably, by the end of 2024, a total of 14,000 malicious packages were identified in open-source projects — a 48% increase compared to the end of 2023 — highlighting the growing threat in this area.

Read the full report on Securelist.com

In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:

  • Provide your SOC team with access to the latest threat intelligence (TI). Kaspersky Threat Intelligence is a single point of access for the company’s TI, providing it with cyberattack data and insights gathered by Kaspersky spanning over 20 years.
  • Upskill your cybersecurity team to tackle the latest targeted threats with Kaspersky online training developed by GReAT experts.
  • For endpoint level detection, investigation, and timely remediation of incidents, implement EDR solutions such as Kaspersky Endpoint Detection and Response.
  • In addition to adopting essential endpoint protection, implement a corporate-grade security solution that detects advanced threats on the network level at an early stage, such as Kaspersky Anti Targeted Attack Platform.
  • As many targeted attacks start with phishing or other social engineering techniques, introduce security awareness training and teach practical skills to your team – for example, through the Kaspersky Automated Security Awareness Platform.
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Gabriel
  • Facebook
  • X (Twitter)

Introvert, wanderer, blogger, foodie, a hip-hop music writer, and one of the co-founders of a tech start-up company called GigsManila.

Related Posts

James Reid Surprises Mom With New Look Using HONOR 600

May 20, 2026

Keeper Security Launches ServiceNow Workflow Integration for Governed Vault Management

May 20, 2026

Keeper Security Launches Agent Kit to Secure AI-Driven Developer Workflows

April 30, 2026
Leave A Reply Cancel Reply

Advertisement
Top Posts

Discover the Latest Must-Visit Shops at SM Malls in the East Metro

May 20, 2026

Delinquent Society Turns Hustle Into Anthem With “Kuha Bag”

May 20, 2026

TGP Franchisees Highlight Purpose-Driven Entrepreneurship Through Stories of Service and Community Impact

May 20, 2026

Pangasinan Joins the Fun as BRGY S2S by Converge Arrives in San Carlos City

May 20, 2026

James Reid Surprises Mom With New Look Using HONOR 600

May 20, 2026
Advertisement
Don't Miss

Discover the Latest Must-Visit Shops at SM Malls in the East Metro

GabrielMay 20, 2026

SM Supermalls brings new food, fashion, and lifestyle spots closer to shoppers in Antipolo, San…

Delinquent Society Turns Hustle Into Anthem With “Kuha Bag”

May 20, 2026

TGP Franchisees Highlight Purpose-Driven Entrepreneurship Through Stories of Service and Community Impact

May 20, 2026

Pangasinan Joins the Fun as BRGY S2S by Converge Arrives in San Carlos City

May 20, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
© 2026 ThemeSphere. Designed by ThemeSphere.
  • Home
  • Lifestyle
  • Tech
  • Travel
  • Review
  • About
  • Contact

Type above and press Enter to search. Press Esc to cancel.