US Warns of 'DeltaCharlie'
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2015-8651 | Integer Overflow in Adobe Flash Player Enables Remote Code Execution CVE-2015-8651 is an integer overflow (CWE-189, a numeric error-handling flaw) in Adobe Flash Player that allows attackers to execute arbitrary code when Flash processes specially crafted content. The realistic trigger is a drive-by web attack: a user browses to a compromised or attacker-controlled page, often reached through malvertising or exploit kits, and the malicious Flash (SWF) content exploits the overflow in the user's browser or standalone player. Successful exploitation gives the attacker code execution in the context of the logged-in user, typically as a delivery mechanism for ransomware, information stealers, or miners, as seen in exploit-kit campaigns of the era (RIG, Neptune, Stegano, and others were distributing Flash exploits at the time). Anyone running an affected version of Adobe Flash Player was exposed; Flash was near-universally deployed in 2015-2016, though the product has since reached end of life (December 31, 2020) and modern browsers no longer load it. Exploitation is confirmed in the wild: CISA added this CVE to its Known Exploited Vulnerabilities catalog on 2022-05-25, EPSS assigns it a 67.9% probability of exploitation in the next 30 days (99th percentile), and no public PoC is cataloged. Do: Uninstall or disable Adobe Flash Player on all remaining systems, since it is end-of-life and CISA's required action is to disconnect/remove it if still in use. If legacy Flash cannot be removed immediately, apply Adobe's January 2016 security update (APSB16-01) and restrict those hosts from untrusted web browsing and ad content. Inventory for standalone Flash players, intranet applications that embed SWF content, and copies of Flash bundled inside other applications. | — | 68% | KEV |
| mass~1 billion+ installations historically (near-universal desktop Flash deployment in 2015-2016); residual exposure today limited to unmigrated legacy systems,… | |
| CVE-2016-0034 | Remote Code Execution via Crafted Website in Microsoft Silverlight 5 CVE-2016-0034 is a memory-corruption flaw in the Microsoft Silverlight 5 runtime, which mishandles negative offsets during decoding, corrupting object headers. An attacker triggers it by convincing a user to visit a crafted website while the vulnerable Silverlight plug-in is active in their browser, requiring no privileges but user interaction. Successful exploitation allows the attacker to execute arbitrary code in the context of the logged-in user (or crash the browser/application). Anyone running Microsoft Silverlight 5 versions before 5.1.41212.0 is affected; Silverlight is now end-of-life, so remaining installations are legacy deployments. The flaw was exploited in the wild through exploit kits such as Angler and RIG to deliver ransomware like Cerber, and it was added to the CISA KEV catalog in May 2022 with known ransomware use. Do: Upgrade Silverlight to version 5.1.41212.0 (January 2016 security update) on any system where it remains installed. Because Silverlight is end-of-life, CISA's KEV required action is to disconnect or remove it and migrate any legacy Silverlight-based web applications; prioritize internet-facing endpoints and users of Internet Explorer/legacy browsers, where the plug-in can still be invoked. | 8.8 | 70% | KEV ransomware |
| masshistorically hundreds of millions of installs (Silverlight reached roughly 70% of consumer devices at peak); residual active installs today likely number in… | |
| CVE-2016-1019 | Arbitrary code execution flaw in Adobe Flash Player, used in ransomware attacks CVE-2016-1019 is a remotely exploitable flaw in Adobe Flash Player that lets an attacker cause a denial of service or, in the worst case, execute arbitrary code on the victim's system. It is triggered remotely, typically when a user views malicious Flash content delivered through a web browser, an application, or a document that embeds Flash content. A successful attack runs code with the privileges of the logged-on user, making the bug a useful foothold for deploying malware, including ransomware. Anyone still running Adobe Flash Player is potentially affected - the product is end-of-life (support ended December 31, 2020), but it persists on legacy desktops, intranet applications, kiosks, and embedded or industrial systems; the CISA data does not list specific affected version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on March 3, 2022, notes known ransomware use, and EPSS assigns a 22.5% probability of exploitation in the next 30 days (98th percentile), though no public proof-of-concept is catalogued. Do: Per CISA's required action, disconnect or remove any system still running Adobe Flash Player, since the product is end-of-life and receives no further security updates; the bug was patched in Adobe's 2016 updates, so only long-unupdated or embedded Flash installs remain vulnerable. Uninstall Flash from browsers and legacy software and confirm that no internal applications or sites still serve or require SWF content. Because exploitation is tied to ransomware campaigns, prioritize user workstations and any internet-facing host with Flash installed. | 9.8 | 22% | KEV ransomware |
| mass≈ millions of legacy endpoints worldwide (Flash historically ran on ~99% of internet-connected PCs; current residual install count unknown) | |
| CVE-2016-4117 | Arbitrary Code Execution in Adobe Flash Player 21.0.0.226 and earlier CVE-2016-4117 is a critical (CVSS 3.1: 9.8) arbitrary code execution vulnerability in Adobe Flash Player 21.0.0.226 and earlier, in which unspecified vectors in the Flash runtime allow remote attackers to execute arbitrary code. It is triggered by delivering malicious Flash content over a network — for example a crafted SWF loaded by a browser or an application that embeds Flash — and, per its CVSS scoring, requires no privileges or authentication. A successful exploit gives the attacker code execution in the context of the Flash runtime (typically the user's browser process), which public reporting shows was used to deliver espionage tooling and, per CISA, is also known to be used in ransomware campaigns. Anyone running Flash Player 21.0.0.226 or earlier was affected, including users of the flash-player packages shipped for Red Hat Enterprise Linux Desktop, Server (including the RHUI variant) and Workstation, openSUSE, openSUSE Evergreen, and SUSE Linux Enterprise Desktop and the SUSE Linux Enterprise Workstation Extension. The bug was exploited in the wild in May 2016 — related headlines tie it to the BlackOasis APT 'Operation Daybreak' espionage campaign using FinFisher — and it was added to the CISA KEV on 2022-03-03 with known ransomware use and a very high 94.4% EPSS. Do: Per CISA's required action, Flash Player is end-of-life: remove or disable Flash wherever it is still present and uninstall the flash-player packages on any remaining RHEL, SUSE or openSUSE hosts, especially internet-facing systems. If a legacy system must keep Flash, ensure it runs a release later than 21.0.0.226 (a fixed build from the May 2016 Adobe update or later) and restrict it from untrusted web content. | 9.8 | 94% | KEV ransomware PoC |
| mass≈100M+ desktop users at the time of disclosure (Flash was then near-universal); residual small base of end-of-life installs today |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 21.0.0.197 | 4 and 19.x vulnerability (CVE-2016-0034) Adobe Flash Player 21.0.0.197 Vulnerability ( CVE-2016-1019 ) Adobe Flash Player 21.0.0.2 |
| ipv4 | 21.0.0.226 | .0.0.197 Vulnerability ( CVE-2016-1019 ) Adobe Flash Player 21.0.0.226 Vulnerability ( CVE-2016-4117 ) The simplest way to defend |
Full article597 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalJun 14, 2017
The United States government has released a rare alert about an ongoing, eight-year-long North Korean state-sponsored hacking operation.
The joint report from the FBI and U.S. Department of Homeland Security (DHS) provided details on "DeltaCharlie," a malware variant used by "Hidden Cobra" hacking group to infect hundreds of thousands of computers globally as part of its DDoS botnet network.
According to the report, the Hidden Cobra group of hackers are believed to be backed by the North Korean government and are known to launch cyber attacks against global institutions, including media organizations, aerospace and financial sectors, and critical infrastructure.
While the US government has labeled the North Korean hacking group Hidden Cobra, it is often known as Lazarus Group and Guardians of Peace – the one allegedly linked to the devastating WannaCry ransomware menace that shut down hospitals and businesses worldwide.
DeltaCharlie – DDoS Botnet Malware
The agencies identified IP addresses with "high confidence" associated with "DeltaCharlie" – a DDoS tool which the DHS and FBI believe North Korea uses to launch distributed denial-of-service (DDoS) attacks against its targets.
DeltaCharlie is capable of launching a variety of DDoS attacks on its targets, including Domain Name System (DNS) attacks, Network Time Protocol (NTP) attacks, and Character Generation Protocol (CGP) attacks.
The botnet malware is capable of downloading executables on the infected systems, updating its own binaries, changing its own configuration in real-time, terminating its processes, and activating and terminating DDoS attacks.
However, the DeltaCharlie DDoS malware is not new.
DeltaCharlie was initially reported by Novetta in their 2016 Operation Blockbuster Malware Report [PDF], which described this as the third botnet malware from the North Korean hacking group, after DeltaAlpha and DeltaBravo.
Other malware used by Hidden Cobra include Destover, Wild Positron or Duuzer, and Hangman with sophisticated capabilities, including DDoS botnets, keyloggers, remote access tools (RATs), and wiper malware.
Hidden Cobra's Favorite Vulnerabilities
Operating since 2009, Hidden Cobra typically targets systems running older, unsupported versions of Microsoft operating systems, and commonly exploits vulnerabilities in Adobe Flash Player to gain an initial entry point into victim's machine.
These are the known vulnerabilities affecting various applications usually exploited by Hidden Cobra:
- Hangul Word Processor bug (CVE-2015-6585)
- Microsoft Silverlight flaw (CVE-2015-8651)
- Adobe Flash Player 18.0.0.324 and 19.x vulnerability (CVE-2016-0034)
- Adobe Flash Player 21.0.0.197 Vulnerability (CVE-2016-1019)
- Adobe Flash Player 21.0.0.226 Vulnerability (CVE-2016-4117)
The simplest way to defend against such attacks is always to keep your operating system and installed software and applications up-to-date, and protect your network assets behind a firewall.
Since Adobe Flash Player is prone to many attacks and just today the company patched nine vulnerability in Player, you are advised to update or remove it completely from your computer.
The FBI and DHS have provided numerous indicators of compromise (IOCs), malware descriptions, network signatures, as well as host-based rules (YARA rules) in an attempt to help defenders detect activity conducted by the North Korean state-sponsored hacking group.
"If users or administrators detect the custom tools indicative of HIDDEN COBRA, these tools should be immediately flagged, reported to the DHS National Cybersecurity Communications and Integration Center (NCCIC) or the FBI Cyber Watch (CyWatch), and given highest priority for enhanced mitigation," the alert reads.
Besides this, the agencies have also provided a long list of mitigations for users and network administrators, which you can follow here.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2017/06/north-korea-hacking-malware.html