Skip to main content

Jason Microsoft Exchange Brute Force Tool

The source code for a new hacking tool named Jason, allegedly used by the OilRig advanced persistent threat group (also known as APT34), has been leaked online.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

The source code for a new hacking tool named Jason, allegedly used by the OilRig advanced persistent threat group (also known as APT34), has been leaked online.


Affected platforms

The following platforms are known to be affected:

Threat details

Jason is used to perform brute force attacks against Microsoft Exchange email servers using pre-compiled lists of usernames and passwords and is controlled by a simple user interface.

Since the source code has become publicly available, it is possible attackers may incorporate Jason into their campaigns or malware.


Remediation steps

Type Step

To limit the potential impact from brute force attacks against Microsoft Exchange email servers ensure that:

  • Strong password policies are in place.
  • Multi-factor authentication is enabled for administrator accounts.
  • Administrator accounts and activity is audited periodically.
  • All operating systems, anti-virus and other security products are kept up to date.
  • All day to day computer activities such as email and internet are performed using non-administrative accounts and that permissions are always assigned based on the principle of least privilege.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.

Further guidance on password administration for system owners is available from the National Cyber Security Centre (NCSC).


Last edited: 14 February 2020 2:43 pm