ZeroHour
Security Affairspublished ()ingested @securityaffairs

North Korea-linked APT Citrine Sleet exploit Chrome zero-day to deliver FudModule rootkit

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38106
Local Privilege Escalation in Microsoft Windows Kernel (CVE-2024-38106)

CVE-2024-38106 is an elevation-of-privilege flaw in the Microsoft Windows kernel caused by a deleted-reference memory-safety weakness (CWE-591), a use-after-free-class bug that corrupts kernel memory. A local attacker with valid low-privileged credentials must run a specially crafted application to trigger the flaw; the attack is local with no user interaction required but is rated high in attack complexity (CVSS:3.1/AV:L/AC:H/PR:L/UI:N, 7.0 High). Successful exploitation elevates the attacker to kernel/SYSTEM-level privileges, giving full control of the compromised host. All supported Windows 10 branches (1507 through 22H2), Windows 11 (21H2 through 24H2), and Windows Server 2016, 2019, and 2022 are affected, meaning essentially the entire current Windows install base. The flaw is confirmed exploited in the wild: CISA added it to the KEV catalog on 2024-08-13, and headlines show it is among the six actively exploited zero-days Microsoft fixed in its August 2024 Patch Tuesday release; no public proof-of-concept is known, and EPSS estimates a 6.3% probability of exploitation in the next 30 days (93rd percentile).

Do: Apply the August 2024 Patch Tuesday cumulative updates (released August 13, 2024) via Windows Update, WSUS, or Intune to every affected Windows 10, Windows 11, or Windows Server instance; this is a KEV-listed, actively exploited bug, so prioritize it in patch cycles. Until patched, restrict local code execution by untrusted or low-privileged users on high-value hosts and hunt for signs of unexpected local privilege escalation. Per CISA's required action, apply vendor mitigations per Microsoft's instructions or discontinue use of affected systems if mitigations are unavailable.

7.06% KEV
  • microsoft Windows 10 1507 all supported builds of the 1507 branch prior to the August 2024 security updates
  • microsoft Windows 10 1607 all supported builds of the 1607 branch prior to the August 2024 security updates
  • microsoft Windows 10 1809 all supported builds of the 1809 branch prior to the August 2024 security updates
  • +9 more
masshundreds of millions of endpoints and servers (essentially every Windows 10, Windows 11, or Windows Server 2016-2022 installation that had not applied the…
CVE-2024-7971
Type Confusion in Google Chromium V8 Enables Heap Corruption via Malicious Pages

Google Chromium's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a remote attacker trigger heap corruption through a specially crafted HTML page. The attack is triggered simply by a user loading an attacker-controlled web page, with no other interaction required. Successful exploitation of heap corruption in a browser JavaScript engine typically gives the attacker code execution within the browser process, a common first step toward broader system compromise. All users of Chromium-based browsers are affected, including Google Chrome, Microsoft Edge, Opera, and any other product embedding Chromium V8. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-08-26, confirming active in-the-wild exploitation, and EPSS assigns a 20.7% probability of exploitation within 30 days (97th percentile).

Do: Update all Chromium-based browsers (Chrome, Edge, Opera, Brave) to the vendors' patched releases immediately and verify the installed version via chrome://version or edge://version. Per CISA's KEV required action, apply vendor mitigations or discontinue use if patches are unavailable; until patching completes, treat web browsing on high-value systems with caution and watch for vendors to publish the specific fixed version numbers.

9.621% KEV PoC
  • Google Chromium V8 JavaScript engine
  • Google Chrome (Chromium-based) All versions built on the affected V8 engine prior to vendor updates (not specified in source data)
  • Microsoft Edge (Chromium-based) All versions built on the affected V8 engine prior to vendor updates (not specified in source data)
  • +1 more
massbillions of users/installations (Chrome alone is estimated at ~3 billion+ users, plus Edge, Opera, Brave and other Chromium browsers)

Indicators of compromiseAll →

TypeIndicatorContext
domainvoyagorclub.spaceere directed to the Citrine Sleet-controlled exploit domain voyagorclub[.]space. While we cannot confirm at this time how the targets wer
Full article444 words · extracted from securityaffairs.com · click to collapse

North Korea-linked APT exploited the recently patched Google Chrome zero-day CVE-2024-7971 to deploy the FudModule rootkit.

North Korea-linked group Citrine Sleet (aka AppleJeus, Labyrinth Chollima, UNC4736, Hidden Cobra) have exploited the recently patched Google Chrome zero-day CVE-2024-7971(CVSS score 8.8) to deploy the FudModule rootkit, states Microsoft.

Microsoft researchers linked with medium confidence the attacks to Citrine Sleet, a North Korean threat actor targeting the cryptocurrency sector for financial gain. However, the FudModule rootkit is also associated with Diamond Sleet, another North Korea-linked cyberespionage group. Microsoft previously identified shared infrastructure and tools between these two groups, suggesting they might be jointly using the FudModule malware.

CVE-2024-7971 affects versions of Chromium before 128.0.6613.84. If exploited, it could enable threat actors to achieve remote code execution (RCE) within the sandboxed Chromium renderer process.

“The observed zero-day exploit attack by Citrine Sleet used the typical stages seen in browser exploit chains. First, the targets were directed to the Citrine Sleet-controlled exploit domain voyagorclub[.]space. While we cannot confirm at this time how the targets were directed, social engineering is a common tactic used by Citrine Sleet. Once a target connected to the domain, the zero-day RCE exploit for CVE-2024-7971 was served.” Microsoft said. “After the RCE exploit achieved code execution in the sandboxed Chromium renderer process, shellcode containing a Windows sandbox escape exploit and the FudModule rootkit was downloaded, and then loaded into memory.”

After successfully escaping the sandbox, the FudModule rootkit was executed in memory. This rootkit uses direct kernel object manipulation (DKOM) techniques to interfere with kernel security mechanisms. The rootkit operates entirely from user mode and tampers with the kernel through a kernel read/write primitive. No further malware activity was observed on the targeted devices.

The sandbox escape exploited the flaw CVE-2024-38106, an elevation of privilege vulnerability in the Windows kernel that Microsoft addressed on August 13, 2024.

“CVE-2024-38106 was reported to Microsoft Security Response Center (MSRC) as being exploited; however, our investigations so far have not suggested any link between the reported CVE-2024-38106 exploit activity and this Citrine Sleet exploit activity, beyond exploiting the same vulnerability.” continues the report. “This may suggest a “bug collision,” where the same vulnerability is independently discovered by separate threat actors, or knowledge of the vulnerability was shared by one vulnerability researcher to multiple actors.”

Microsoft recommends organizations to keep systems up to date and use security solutions that provide unified visibility across the cyberattack chain to detect and block post-compromise attacker tools and malicious activity following exploitation. Microsoft also recommends strengthening operating environment configuration.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, Chrome zero-day)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/167848/breaking-news/north-korea-linked-apt-exploited-chrome-zero-day-cve-2024-7971.html