North Korean Hackers Targeting Healthcare with Ransomware to Fund its Operations
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20038 | Unauthenticated Stack Buffer Overflow in SonicWall SMA 100 Appliances SonicWall SMA 100 series secure remote-access appliances contain an unauthenticated stack-based buffer overflow (CWE-121) in the appliance's network-facing interface, triggered by crafted requests sent to the device without any credentials. A remote attacker who triggers the overflow can execute arbitrary code on the appliance with the privileges of the affected service, gaining a foothold on an internet-facing VPN gateway that typically sits at the network edge. Any organization running an SMA 100 series appliance is affected, and because these appliances provide remote access to corporate networks, compromise can expose entire internal environments. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2022-01-28 with known ransomware use, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is catalogued in the provided data, but the KEV listing and EPSS score indicate active attacker interest. Do: Upgrade SMA 100 series appliances to firmware 10.0.7.2 or later per SonicWall's instructions, as required by the CISA KEV listing. Until patched, restrict internet exposure of the SMA portal and management interface to trusted sources where feasible. Because ransomware operators are known to exploit this flaw, review appliance logs for signs of compromise and monitor for unexpected account creation or traffic after patching. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed SMA 100 appliances (order of magnitude ~10,000-50,000 devices), plus a larger installed base used internally | |
| CVE-2022-24990 | Unauthenticated RCE via Admin Password Leak in TerraMaster TOS 4.2.29 and earlier TerraMaster TOS (TerraMaster OS) versions 4.2.29 and earlier do not require authentication (CWE-306) on the mobile API endpoint module/api.php?mobile/webNasIPS, and a request presenting the User-Agent "TNAS" returns system information that includes the administrative account's password in the PWD field. An unauthenticated attacker with network access to the NAS web interface can send this request and read the response, obtaining full administrative credentials. With those credentials an attacker controls the NAS, and public proof-of-concept exploits chain this flaw with a PHP object-instantiation bug to achieve unauthenticated remote command execution. Any TerraMaster NAS running TOS 4.2.29 or earlier is affected, with internet-exposed devices at the greatest risk. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities Catalog (added 2023-02-10) with known ransomware use, carries an EPSS of roughly 84%, and CISA and press reports describe active attacks, including North Korean ransomware activity against healthcare and critical infrastructure. Do: Upgrade TerraMaster TOS to a release newer than 4.2.29 per the vendor's instructions, as required by the CISA KEV entry. If patching must wait, restrict the TOS web interface to trusted networks so unauthenticated users cannot reach module/api.php?mobile/webNasIPS. Check device logs for requests to the webNasIPS endpoint with a TNAS User-Agent and look for signs of post-compromise activity, since ransomware use of this flaw is known. | 7.5 | 84% | KEV ransomware PoC ×3 |
| largeon the order of tens of thousands of internet-exposed TerraMaster NAS devices (estimate, not a verified count) |
Full article526 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananFeb 10, 2023Threat Intelligence / Ransomware
State-backed hackers from North Korea are conducting ransomware attacks against healthcare and critical infrastructure facilities to fund illicit activities, U.S. and South Korean cybersecurity and intelligence agencies warned in a joint advisory.
The attacks, which demand cryptocurrency ransoms in exchange for recovering access to encrypted files, are designed to support North Korea's national-level priorities and objectives.
This includes "cyber operations targeting the United States and South Korea governments — specific targets include Department of Defense Information Networks and Defense Industrial Base member networks," the authorities said.
Threat actors with North Korea have been linked to espionage, financial theft, and cryptojacking operations for years, including the infamous WannaCry ransomware attacks of 2017 that infected hundreds of thousands of machines located in over 150 countries.
Since then, North Korean nation-state crews have dabbled in multiple ransomware strains such as VHD, Maui, and H0lyGh0st to generate a steady stream of illegal revenues for the sanctions-hit regime.
Besides procuring its infrastructure through cryptocurrency obtained via its criminal activities, the adversary is known to create fake personas, function under third-party foreign affiliate identities, employ intermediaries, and utilize VPNs to conceal its origins.
Attack chains mounted by the hacking crew entail the exploitation of known security flaws in Apache Log4j, SonicWall, and TerraMaster NAS appliances (e.g., CVE 2021-44228, CVE-2021-20038, and CVE-2022-24990) to gain initial access, following it up by reconnaissance, lateral movement, and ransomware deployment.
In addition to using privately developed ransomware, the actors have been observed leveraging off-the-shelf tools like BitLocker, DeadBolt, ech0raix, Jigsaw, and YourRansom for encrypting files, not to mention even impersonating other ransomware groups such as REvil.
The inclusion of DeadBolt and ech0raix is notable as it marks the first time government agencies have formally tied the ransomware strains, which are notable for repeatedly targeting QNAP NAS devices, to a specific adversarial group.
Also employed as an alternative method to distribute the malware is via trojanized files of a messenger app called X-Popup in attacks targeting small and medium-size hospitals in South Korea.
As mitigations, the agencies recommend organizations to implement the principle of least privilege, disable unnecessary network device management interfaces, enforce multi-layer network segmentation, require phishing-resistant authentication controls, and maintain periodic data backups.
The alert comes as a new report from the United Nations found that North Korean hackers stole record-breaking virtual assets estimated to be worth between $630 million and more than $1 billion in 2022.
The report, seen by the Associated Press, said the threat actors used increasingly sophisticated techniques to gain access to digital networks involved in cyberfinance, and to steal information from governments, companies, and individuals that could be useful in North Korea's nuclear and ballistic missile programs.
It further called out Kimsuky, Lazarus Group, and Andariel, which are all part of the Reconnaissance General Bureau (RGB), for continuing to target victims with the goal of creating revenue and soliciting information of value to the hermit kingdom.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/02/north-korean-hackers-targeting.html