ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Iranian Hackers Hid in Albanian Networks for Over a Year

highRansomwareimportance 60CVE-2019-0604

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0604
RCE in Microsoft SharePoint via Application Package Markup Validation Flaw

Microsoft SharePoint fails to check the source markup of an application package, an improper input validation flaw (CWE-20) that allows maliciously crafted markup to be processed by the server. An attacker triggers the flaw by getting an affected SharePoint server to handle a crafted application package, without any special privileges described in the disclosure. Successful exploitation lets the attacker run remote code in the context of the SharePoint application pool and the SharePoint server farm account, providing control of the web server and access to a highly privileged farm-level identity. Any organization running an affected on-premises Microsoft SharePoint deployment is exposed, with internet-facing SharePoint servers at greatest risk. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and EPSS puts the probability of exploitation at 99.9%, although no public proof-of-concept is catalogued.

Do: Apply Microsoft's SharePoint security updates per vendor instructions immediately, prioritizing internet-exposed SharePoint servers as CISA's required action directs. Given known in-the-wild and ransomware use, hunt for signs of compromise such as unexpected .aspx or webshell files in SharePoint directories and anomalous use of the SharePoint farm account. Restrict or firewall internet exposure of SharePoint servers until patches are confirmed applied.

9.8100% KEV ransomware
  • Microsoft SharePoint
mass≈ hundreds of thousands of on-prem SharePoint server deployments worldwide, of which tens of thousands are directly internet-facing (estimate)
Full article391 words · extracted from infosecurity-magazine.com · click to collapse

State-backed Iranian threat actors were able to remain undetected inside an Albanian government network for 14 months before deploying destructive malware in July 2022, a new report has revealed.

The US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI released the joint alert to shed more light on the campaign, which resulted in Albania severing diplomatic ties with Iran – the first time a cyber-incident has led to such an outcome.

Identifying the attack group as the state-sponsored ‘HomeLand Justice,’ the report claimed that initial access was achieved by exploitation of CVE-2019-0604, a remote code execution bug in SharePoint. The vulnerability, which has a CVSS score of 8.6, was flagged by the UK’s National Cyber Security Centre (NCSC) in October 2020.

A few days after gaining network access, the threat actors proceeded to a persistence and lateral movement phase, using several .aspx webshells for persistence and RDP, SMB and FTP for lateral movement.

Between one and six months after initial access they compromised a Microsoft Exchange account and began probing for an admin account, the report claimed.

The US authorities claimed HomeLand Justice managed to exfiltrate significant volumes of email data. The group also managed to compromise two victim VPN accounts.

Finally, 14 months after the start of the operation they deployed a ransomware-style file encryptor and disk-wiping malware.

The campaign itself seems to have been a response to Albania’s sheltering of Iranian opposition group Mujahideen-e-Khalq (MEK). After Albania cut diplomatic ties with Iran in September 2022, the attackers used similar tactics to launch another wave of attacks, this time impacting border control systems.

In this case, attribution seems to have been pretty straightforward. HomeLand Justice claimed credit for the campaign, posting videos of the attack on its website and leaking information that it had stolen, according to CISA.

The incident is another reminder of the need for effective detection and response tooling to minimize attacker dwell-time, which globally stands at a median of 21 days.

“Between May and June 2022, Iranian state cyber actors conducted lateral movements, network reconnaissance, and credential harvesting from Albanian government networks,” noted the report.

“In July 2022, the actors launched ransomware on the networks, leaving an anti-Mujahideen-e-Khalq (MEK) message on desktops. When network defenders identified and began to respond to the ransomware activity, the cyber actors deployed a version of ZeroCleare destructive malware.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/iranian-hackers-albanian-networks/