Chinese APT Groups Linked to Ransomware Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0213 | Local Privilege Escalation in Microsoft Windows COM Aggregate Marshaler CVE-2017-0213 is an elevation of privilege flaw in the Windows COM Aggregate Marshaler affecting Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 (1507/1511/1607/1703), and Windows Server 2008 SP2/R2 SP1 through Server 2016. It is triggered when a local, low-privileged user runs a specially crafted application that abuses COM aggregate marshaling; there is no remote or network attack vector, and user interaction is required. Successful exploitation lets the attacker execute code with elevated privileges (up to SYSTEM) on the local machine, typically as a step toward full host compromise, and CISA notes known ransomware use. All users of the listed Windows client and server versions are affected; the flaw was fixed in Microsoft's May 2017 Patch Tuesday. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28, ransomware use known), a public PoC exists (Exploit-DB 42020), and EPSS assigns a top-percentile 84.1% probability of exploitation in the next 30 days. Do: Apply Microsoft's May 2017 security update for this COM elevation-of-privilege flaw, or later monthly/cumulative rollups, on every affected Windows 7/8.1/RT 8.1/10 and Server 2008/2012/2016 system, prioritizing hosts where untrusted users can run applications (terminal/RDS servers, shared workstations, VDI). Inventory installed updates to confirm patching, and give legacy Windows 7/Server 2008/2012 estates special attention because this bug has documented ransomware-linked exploitation; if compromise is suspected, hunt for local privilege-escalation artifacts and follow the KEV required action of applying vendor updates. | 7.3 | 84% | KEV ransomware PoC |
| masshundreds of millions of Windows systems (Windows 7/8.1/10-era desktop and server installed base) |
Full article332 words · extracted from infosecurity-magazine.com · click to collapse
A well-known Chinese state-backed APT group is believed to have been responsible for multiple ransomware attacks against firms last year, according to new research.
A report from Security Joes and Pro reveals how the vendors uncovered the links after investigating an incident in which ransomware encrypted “several core servers” at an unidentified victim organization.
They found samples of malware linked to the DRBControl campaign which targeted major gaming companies and is associated with two well-known Chinese-backed groups, APT27 (aka Emissary Panda) and Winnti.
Specifically, they claimed to have detected an older version of the Clambling backdoor used in that campaign, an ASPXSpy webshell previously used by APT27, and the PlugX RAT which is often used in Chinese attacks.
Although Winnti is known for financially motivated attacks, APT27 is generally more focused on data theft. However, the latter has previously been linked to one ransomware attack, featuring the Polar variant.
“There are extremely strong links to APT27 in terms of code similarities and TTPs,” the report noted. “This incident occurred at a time when where COVID-19 was rampant across China with lockdowns being put into place, and therefore a switch to a financial focus would not be surprising.”
The attack itself does not seem to have been particularly sophisticated.
The initial vector was a third-party service provider that itself had been infected by a third party, and the attackers used Windows own BitLocker encryption tool to lock down targeted servers.
ASPXSpy was deployed for lateral movement and PlugX and Clambling were loaded into memory using a Google Updater executable vulnerable to DLL side-loading. Popular open source tool Mimikatz was also used in the attack and a publicly available exploit for CVE-2017-0213 was used to escalate privileges.
Gaming firms are an increasingly popular target among financially motivated attackers, according to new research released yesterday by Kela. The threat intelligence firm claimed to have discovered one million compromised internal accounts from gaming companies on the dark web, and 500,000 breached credentials belonging to employees.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/chinese-apt-group-linked-to/