A suspected Ukrainian APT group is behind a hacking campaign that planted keyloggers on the login pages of Exchange servers.

Russian security firm Positive Technologies has linked the attacks to a group known as PhantomCore.