Forum Discussion
Exchange Server was exploit and used to send spam email
Hello Don,
We are investiging similar messages and messages primarily for non existing domains in our environments. In our case mostly for .com.br and .com.ar domains, although totally not relevant for any of our organizations. We don’t expect any of our organizations is compromised and so far we trace it back to a new form of spoofing or tricking spamfilters. All out Exchange farms are behind different isolated relay solutions.
Mails are related to payments and bitcoin frauds. Also classical “we see what you are doing online” messages.
So far we see it has stopped at dec4 22:10 EU time.
I will update here if we find some interesting details that are worth sharing.
In any case I suggest you to send an internal message that users should be careful.
Kind regards,
Christiaan