ZeroHour
Malware

BADNEWS

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent

Unit 42 details Patchwork APT campaigns against the Indian subcontinent using EPS exploits and an updated BADNEWS backdoor targeting Pakistani military and nuclear interests.

Unit 42 observed the Patchwork group (also known as Dropping Elephant and Monsoon) conducting campaigns against targets in the Indian subcontinent using weaponized documents that exploit CVE-2015-2545 and CVE-2017-0261. The documents deliver an updated BADNEWS backdoor that grants attackers full control of victim machines, using dead drop resolvers on legitimate third-party websites for C2 and HTTP for communications. Lures referenced Pakistan Army promotions, the Pakistan Atomic Energy Commission and the Ministry of the Interior, and in late January 2018 the group shifted from CVE-2017-0261 to the older CVE-2015-2545.

Palo Alto Unit 42 · 29d agoThreat actor in the wildCVE-2015-2545CVE-2017-0261

Related CVEs

  • Use-After-Free RCE in Microsoft Office 2010/2013/2016
    CVE-2017-0261 is a use-after-free (CWE-416) remote code execution flaw in Microsoft Office 2010 SP2, 2013 SP1, and 2016, caused by improper handling of objects in memory. It is triggered by convincing a user to open a malicious document or email attachment, which corrupts memory and lets the attacker run arbitrary code with the victim's privileges (high impact on confidentiality, integrity, and availability). Any user of the affected Office editions is exposed, and because the attack requires user interaction via a crafted file, email-borne targeting is the realistic attack path. The flaw was patched in Microsoft's May 2017 Patch Tuesday releases after being exploited as a zero day, with public reporting linking active exploitation to Russian APT groups. It is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), and its EPSS score of 78.1% (100th percentile) reflects a very high likelihood of exploitation.
    · Microsoft Office 2010 Service Pack 2 · Microsoft Office 2013 Service Pack 1 KEVmass
  • Malformed EPS Image RCE in Microsoft Office
    Microsoft Office fails to properly validate Encapsulated PostScript (EPS) images embedded in documents (CWE-20, improper input validation), and processing a specially crafted EPS image can allow arbitrary code execution. The flaw is triggered when a victim opens an Office document—typically delivered via email—that contains the malicious EPS image, with no user interaction beyond opening the file. Successful exploitation gives the attacker code execution with the privileges of the logged-in user, a technique espionage groups targeting embassies, government entities and the Indian subcontinent (e.g., Patchwork, Ke3chang-related campaigns) have used to deliver backdoors such as the BADNEWS RAT. Any organization running Microsoft Office builds that lack the relevant Office updates is affected, with historically exposed populations concentrated in government and diplomatic networks using legacy Office. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) and carries a very high EPSS (~86%), indicating active exploitation despite the fix being available since 2015.
    · Microsoft Office KEVmass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.