ZeroHour
Vendor

Palo Alto Unit 42

0 mentions in 7 days · 4 in 30 days · 4 total · first seen · last

Timeline

Identity Abuse Through Trusted Communication Channels

Unit 42 explains how attackers abuse trusted enterprise communication and collaboration channels for identity phishing and credential theft, and outlines defenses.

Palo Alto Unit 42 details how attackers exploit enterprise collaboration and communication tools as trusted channels for identity phishing and credential theft. The writeup describes abuse of presumed-trusted messaging paths and outlines defense strategies. It is guidance rather than a report of a specific incident.

Palo Alto Unit 42 · 26d agoPhishing & fraud

Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent

Unit 42 details Patchwork APT campaigns against the Indian subcontinent using EPS exploits and an updated BADNEWS backdoor targeting Pakistani military and nuclear interests.

Unit 42 observed the Patchwork group (also known as Dropping Elephant and Monsoon) conducting campaigns against targets in the Indian subcontinent using weaponized documents that exploit CVE-2015-2545 and CVE-2017-0261. The documents deliver an updated BADNEWS backdoor that grants attackers full control of victim machines, using dead drop resolvers on legitimate third-party websites for C2 and HTTP for communications. Lures referenced Pakistan Army promotions, the Pakistan Atomic Energy Commission and the Ministry of the Interior, and in late January 2018 the group shifted from CVE-2017-0261 to the older CVE-2015-2545.

Palo Alto Unit 42 · 29d agoThreat actor in the wildCVE-2015-2545CVE-2017-0261

RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families

Unit 42 names RANCOR, a previously unidentified espionage group targeting Southeast Asian political entities with newly discovered PLAINTEE and DDKONG malware families.

Unit 42 tracks a previously unidentified group it dubs RANCOR conducting highly targeted espionage attacks in Singapore and Cambodia using two custom malware families, DDKONG and PLAINTEE. Attacks appear to have begun with spear phishing, with decoy political news documents hosted on legitimate sites including a Cambodian government website and Facebook. Infrastructure links to IP 89.46.222[.]97 and KHRAT-associated domains such as facebook-apps[.]com, and the activity is grouped into two clusters tied together by PLAINTEE usage and similar targeting.

Palo Alto Unit 42 · 29d agoThreat actor1

Upatre Continued to Evolve with new Anti

Unit 42 analyzes an undocumented Upatre downloader variant with VM detection via process hashing, packed code, disabled Windows defenses and Namecoin .bit C2 domains.

Unit 42 analyzed an Upatre downloader variant compiled in December 2016 that went largely undetected by automated systems, featuring heavy code flow obscuration, on-demand decryption of network communications, and novel virtual machine detection. The sample enumerates running processes, computes CRC32 hashes XORed with a hard-coded key, and sleeps if analysis-related processes such as vmtoolsd.exe or python.exe are found. It masquerades with Google Chrome icons, disables Windows Defender, Firewall and other security services, injects code into msiexec.exe, and resolves .bit Namecoin domains like bookreader[.]bit via hardcoded OpenNIC DNS servers over TCP.

Palo Alto Unit 42 · 29d agoMalware1

Related CVEs

  • Use-After-Free RCE in Microsoft Office 2010/2013/2016
    CVE-2017-0261 is a use-after-free (CWE-416) remote code execution flaw in Microsoft Office 2010 SP2, 2013 SP1, and 2016, caused by improper handling of objects in memory. It is triggered by convincing a user to open a malicious document or email attachment, which corrupts memory and lets the attacker run arbitrary code with the victim's privileges (high impact on confidentiality, integrity, and availability). Any user of the affected Office editions is exposed, and because the attack requires user interaction via a crafted file, email-borne targeting is the realistic attack path. The flaw was patched in Microsoft's May 2017 Patch Tuesday releases after being exploited as a zero day, with public reporting linking active exploitation to Russian APT groups. It is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), and its EPSS score of 78.1% (100th percentile) reflects a very high likelihood of exploitation.
    · Microsoft Office 2010 Service Pack 2 · Microsoft Office 2013 Service Pack 1 KEVmass
  • Malformed EPS Image RCE in Microsoft Office
    Microsoft Office fails to properly validate Encapsulated PostScript (EPS) images embedded in documents (CWE-20, improper input validation), and processing a specially crafted EPS image can allow arbitrary code execution. The flaw is triggered when a victim opens an Office document—typically delivered via email—that contains the malicious EPS image, with no user interaction beyond opening the file. Successful exploitation gives the attacker code execution with the privileges of the logged-in user, a technique espionage groups targeting embassies, government entities and the Indian subcontinent (e.g., Patchwork, Ke3chang-related campaigns) have used to deliver backdoors such as the BADNEWS RAT. Any organization running Microsoft Office builds that lack the relevant Office updates is affected, with historically exposed populations concentrated in government and diplomatic networks using legacy Office. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) and carries a very high EPSS (~86%), indicating active exploitation despite the fix being available since 2015.
    · Microsoft Office KEVmass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.