ZeroHour
Security Affairspublished ()ingested @securityaffairs

Blue Termite APT group focuses on Japanese organizations

highThreat actorimportance 60CVE-2015-5119

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-5119
Use-After-Free RCE in Adobe Flash Player (ActionScript 3 ByteArray)

CVE-2015-5119 is a use-after-free memory-corruption vulnerability (CWE-119) in the ActionScript 3 ByteArray class of Adobe Flash Player. It is triggered when Flash processes crafted ActionScript/SWF content — typically a malicious .swf loaded from a web page, advertisement, email attachment, or document — causing Flash to access already-freed memory in an attacker-controllable way. A successful attack gives the adversary remote code execution in the context of the user running Flash. Anyone with Adobe Flash Player installed was exposed; at disclosure Flash was on the vast majority of internet-connected desktops, and today risk is concentrated in legacy browsers, office/document tooling, industrial or enterprise applications, and other systems where Flash was never removed. Exploitation status: this flaw has long-standing in-the-wild use (related headlines tie the leaked Hacking Team Flash exploit to APT campaigns against Japanese, East Asian, and US Government targets and to top 2016 exploit kits), it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS assigns a 99.3% probability of exploitation within 30 days.

Do: Because Flash Player is end-of-life, CISA's required action is to disconnect it rather than patch: audit browsers, document/office tooling, and legacy or industrial applications for Flash dependencies and fully uninstall or disable Flash and any embedded SWF players. If a system must keep Flash temporarily, verify it runs a patched build from 2015 or later (Adobe's July 2015 emergency update, APSB15-16, addressed this flaw) and block untrusted SWF content via browser settings, email gateway, and web filtering. Prioritize cleanup on internet-facing endpoints and users who browse the web or open untrusted email attachments, the typical delivery route for this exploit.

99% KEV
  • Adobe Flash Player
mass≈ millions of legacy desktop installations
Full article504 words · extracted from securityaffairs.com · click to collapse

Security experts at Kaspersky Lab have analyzed the cyber attacks run by the Blue Termite APT, a hacking crew group focused on Japanese organizations.

According to the experts at Kaspersky security firm, an ATP group dubbed Blue Termite has been active since at least November 2013 focusing its attacks on Japanese organizations. The Blue Termite APT crew hit also other organizations worldwide, but most of its control infrastructure (C&C servers) are located in Japan.

The list of targets is long and includes government agencies, financial services firms, banks, universities, public interest groups, news companies, and various organizations from sectors such as automotive, healthcare, chemical, electrical, real estate, food, construction, insurance, transportation, robotics, semiconductors, and information services.

According to the experts the Blue Termite APT is responsible for the recently data breach suffered by the Japan Pension Service that exposed personal details of 1.25 million people.

The researcher noticed a spike in the number of infection related the Blue Termite since July, the APT is still active. In July the group start leveraging a Flash Player exploit (CVE-2015-5119) leaked following the Hacking Team hack, the APT used the Flash Player exploit in spear-phishing emails to infect victims before its public disclosure.

In July, the Blue Termite hackers deployed the Hacking Team exploit on several compromised Japanese websites in order to deliver the malware for its campaign via drive-by-download attacks.

In some cases, the APT conducted surgical operation infecting only the computers of certain users, they adopted the watering hole attack against a prominent member of the Japanese government.

In another case the Blue Termite hackers used a script to ensure that only users who visited the compromised website from the IP addresses of a certain Japanese organization would be infected.

Blue Termite has been leveraging customized data stealer belonging the Emdivi family.

“Kaspersky Lab detected the tailored malware, “emdivi t20″. This malware is basically used after the infection by emdivi t17 that serves as a backdoor. Although the versions emdivi t17 and emdivi t20 are from the same emdivi family, the latter is more sophisticated.” states the post published on SecureList.

“One of the most interesting things about the malware used by the Blue Termite actor is that each victim is supplied with a unique malware sample that is made in a way that it could only be launched on a specific PC, targeted by the Blue Termite actor,” Kaspersky said.

The attribution is not simple dealing with APT, but experts at Kaspersky speculate the attackers are likely Chinese speakers.

Kaspersky isn’t the unique firm that analyzed the Blue Termite APT, Symantec has also been monitoring it, in November 2014 the company published a report on a cyber espionage campaign dubbed “CloudyOmega.”

Symantec reported that the APT group behind the CloudyOmega operation is linked with the Hidden Lynx APT and the threat actor responsible for the “LadyBoyle” attacks.

Trend Micro also published a report on the APT.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – Blue Termite, APT)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/39472/cyber-crime/blue-termite-apt.html