ZeroHour
The Recordpublished ()ingested

Amnesty International breach linked to Chinese government, investigation finds

criticalData breachimportance 60CVE-2021-40539

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-40539
Unauthenticated RCE via REST API auth bypass in Zoho ManageEngine ADSelfService Plus

CVE-2021-40539 is a critical (CVSS 9.8) authentication bypass in the REST API of Zoho ManageEngine ADSelfService Plus, caused by use of an incorrectly resolved name or reference (CWE-706). An unauthenticated, network-adjacent or internet-reachable attacker sends specially crafted requests to the product's REST API, bypassing authentication, and can chain the bypass to full remote code execution with no privileges or user interaction required. Successful exploitation yields complete compromise of the self-service portal server (high impact to confidentiality, integrity and availability); public reporting and vendor notes document attackers dropping malicious code and web shells onto vulnerable servers. Any organization running ManageEngine ADSelfService Plus build 6113 or earlier is affected, which typically means enterprise Microsoft Active Directory environments running this widely deployed self-service password/SSO portal. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS puts the 30-day exploitation probability at 99% (100th percentile), Microsoft warned that Chinese threat actors were actively exploiting it, a public proof-of-concept is available, and it ranked among CISA's most routinely exploited vulnerabilities.

Do: Immediately upgrade ManageEngine ADSelfService Plus to a fixed build newer than 6113 per the vendor's update instructions, as required by CISA. Because exploitation predates patching and the flaw has been used to drop malicious code, check ADSelfService Plus servers for web shells, unexpected scheduled tasks, and unexplained accounts/processes, and hunt for indicators from the published analyses. Where possible, restrict internet exposure of the ADSelfService Plus REST API while patching, prioritized for externally reachable instances.

9.899% KEV ransomware PoC
  • Zoho (zohocorp) ManageEngine ADSelfService Plus 6113 and prior
largetens of thousands of enterprise server installations (unknown precise count)
Full article562 words · extracted from therecord.media · click to collapse

Amnesty International's Canadian branch suffered a data breach by a group allegedly sponsored by the Chinese government, according to a statement from the organization this week. 

The human rights organization said it discovered the breach on October 5 after employees detected activity they deemed “suspicious” on their IT infrastructure. The organization hired forensic investigators and cybersecurity experts from Secureworks to examine the situation. 

Secureworks determined that tools and techniques associated with specific advanced persistent threat (APT) groups indicated that the breach was likely conducted by “a threat group sponsored or tasked by the Chinese state.”

Amnesty International Canada and Secureworks did not explain what specifically led them to this conclusion, with the human rights giant saying the assessment was based “on the nature of the targeted information as well as the observed tools and behaviors, which are consistent with those associated with Chinese cyberespionage threat groups.”

“This case of cyberespionage speaks to the increasingly dangerous context which activists, journalists, and civil society alike must navigate today. Our work to investigate and denounce these acts has never been more critical and relevant,” Ketty Nivyabandi, secretary general of Amnesty International Canada, said in a statement.

“We will continue to shine a light on human rights violations wherever they occur and to denounce the use of digital surveillance by governments to stifle human rights.”

Amnesty International Canada said it decided to speak out about the incident to warn other human rights organizations about the increased threat they now face, particularly from state-backed groups intent on siphoning critical information and disrupting human rights work. Secureworks lauded the organization for being open about the attack.

“Amnesty International Canada’s openness and transparency about recent events will undoubtedly help all organizations facing persistent and sophisticated threat actors," said Barry Hensley, chief threat intelligence officer at Secureworks.

Earlier this year, the Red Cross dealt with a wide-ranging hack that targeted a program called Restoring Family Links, which is a web-based system used by Red Cross volunteers to reunite family members separated by conflict, disaster, or migration. 

The Red Cross said there were indicators that the attack was conducted by a state-sponsored group and noted that the hackers gained entry using CVE-2021-40539 – a vulnerability affecting password management company Zoho commonly used by a Chinese state-sponsored group known as APT27.

Several other campaigns against human rights groups and activists have been uncovered this year, including attacks on the Uyghur community as well as activists, journalists, diplomats and politicians working in the Middle East

Amnesty International Canada did not say what information was stolen during the attack on their infrastructure but noted that no membership or donor data was taken. The organization has already contacted law enforcement and is taking several measures to strengthen its digital security. 

“As an organization advocating for human rights globally, we are very aware that we may be the target of state-sponsored attempts to disrupt or surveil our work,” Nivyabandi said. 

“These will not intimidate us and the security and privacy of our activists, staff, donors, and stakeholders remain our utmost priority.” 

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/amnesty-international-breach-linked-to-chinese-government-investigation-finds