ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

APT Hacker Group Bitter Continues to Attack Military Targets in Bangladesh

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0798
Memory Corruption RCE in Microsoft Office Equation Editor (CVE-2018-0798)

CVE-2018-0798 is a memory corruption flaw (out-of-bounds write, CWE-787) in the Microsoft Equation Editor component of Microsoft Office 2007, 2010, 2013, and 2016 that allows remote code execution when the component mishandles objects in memory. A remote attacker triggers it by persuading a user to open a specially crafted document containing a maliciously embedded equation; user interaction is required and no privileges are needed (CVSS vector AV:N/AC:L/PR:N/UI:R). Successful exploitation lets the attacker run arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Any organization running the affected legacy Office versions — including deployments using the Office Compatibility Pack — is exposed, with government, military, and transportation organizations named in related reporting on Office-document attack campaigns. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and its EPSS score of 95.1% (100th percentile) indicates a very high probability of active exploitation, with related headlines highlighting APT activity (notably the Bitter group's campaigns against military targets in South Asia) around Office document threats.

Do: Apply Microsoft's security updates for this vulnerability across Office 2007, 2010, 2013, 2016 and the Office Compatibility Pack, per vendor instructions as required by CISA KEV, and upgrade off legacy Office 2007/2010 to a still-supported release since those versions no longer receive regular fixes. Enforce caution with untrusted Office documents (don't open unsolicited attachments or embedded equations from unknown sources) and consider stripping or blocking embedded OLE equation objects from external files. Prioritize patching for government, military, and transportation-sector environments given active APT targeting of those sectors via Office documents.

8.895% KEV
  • Microsoft Office (Equation Editor) Office 2007, Office 2010, Office 2013, Office 2016
  • Microsoft Office Compatibility Pack
  • Microsoft Word
masshundreds of millions of Office users/endpoints worldwide
Full article313 words · extracted from infosecurity-magazine.com · click to collapse

An advanced persistent threat (APT) operating under the name of ‘Bitter’ continues to conduct cyber-attacks against military entities in Bangladesh.

The news comes from a team of SecuInfra cybersecurity experts, who published an advisory on Tuesday describing the south-Asian APT’s recent campaigns. 

“Through malicious document files and intermediate malware stages, the threat actors conduct espionage by deploying Remote Access Trojans,” reads the document.

The SecuInfra findings build on a report published by Talos last May (which disclosed the group’s expansion and intentions to hit Bangladeshi government organizations) and cover an attack presumably conducted in mid-May 2022.

Specifically, the attack would have originated from a weaponized Excel document likely distributed through a spear-phishing email.

When opened, the email would take advantage of the Microsoft Equation Editor exploit (CVE-2018-0798) to drop a payload named ZxxZ from a remote server.

The malicious code would then be implemented in Visual C++ and work as a second-stage implant, allowing malicious actors to deploy additional malware.

“Comparing this fingerprinting function to the one documented by Cisco Talos we can see that Bitter abandoned the ZxxZ value separator (that gave the Downloader its name) in exchange for a simple underscore.”

According to SecuInfra, the APT did this to avoid detection through IDS/IPS systems based on this specific separator.

“The Bitter threat group continues to use their exploitation approach in Asia with themed lures and internal changes to avoid existing detections,” SecuInfra explained.

To protect from such attacks, the security researchers said companies and governments should regularly implement network and endpoint detection and response measures and patch commonly exploited software like Microsoft Office.

“We will continue to monitor this threat group and report on changes in their Tactics, Techniques and Procedures.”

All of the samples mentioned in the SecuInfra advisory have been reportedly made available through the public Malware repositories MalwareBazaar and Malshare for verification and further research.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/apt-bitter-attack-military/