“Kaspersky Lab experts have discovered a hard-to-detect backdoor (malicious program designed for hidden remote control of a computer) SessionManager,” the company’s website says in a statement.

It is noted that the program allows you to access the corporate IT infrastructure, as well as perform a wide range of malicious actions, including reading corporate mail, distributing malicious software and remotely managing infected servers.

“The attackers inject the malware remotely as a module for Microsoft IIS, a set of web services that includes the Exchange mail server.

Any employee of the company faces the work of this server when using Microsoft corporate mail, ”the company explained.

According to experts, the first attacks using the SessionManager were detected at the end of March 2021.

“Victims are predominantly government agencies and non-profit organizations in Africa, South Asia, Europe and the Middle East, as well as in Russia,” Kaspersky Lab said.

It is noted that so far the backdoor has been found on 34 servers in 24 companies. 

Earlier, Kaspersky Lab cybersecurity expert Viktor Chebyshev, in an interview with Gazeta.Ru, spoke about the signs of viruses in a smartphone.