ZeroHour
Security Affairspublished ()ingested @securityaffairs

Recently Cloud Atlas used a new piece of polymorphic malware

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-11882
Memory Corruption RCE in Microsoft Office via Legacy Equation Editor

CVE-2017-11882 is a memory corruption vulnerability (CWE-119) in Microsoft Office, residing in the legacy Microsoft Equation Editor component (EQNEDT32.EXE), that allows remote code execution in the context of the current user. Attackers trigger it by persuading a user to open a crafted document, most commonly an RTF file or other Office document carrying a malicious embedded equation object, which overflows a buffer while the equation content is parsed. Successful exploitation lets the attacker run arbitrary code with the privileges of the signed-in user, a typical foothold for malware delivery and, per CISA, for ransomware operations. Any environment running affected Microsoft Office builds is exposed; the source data does not enumerate specific affected version ranges. The flaw is confirmed exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and holds a 99.9% EPSS score (percentile 100), though the source data lists no public PoC.

Do: Apply Microsoft's Office security updates (November 2017 or later) across all endpoints, prioritizing this KEV-listed flaw given its known ransomware use. On systems that cannot yet be patched, disable or unregister the legacy Equation Editor (EQNEDT32.EXE) and consider blocking or warning on RTF attachments as interim mitigations. Check for indicators of abuse such as EQNEDT32.EXE spawning unexpected child processes after document opens.

7.8100% KEV ransomware PoC ×10
  • Microsoft Office
masshundreds of millions of users/installations (Office is near-ubiquitous on Windows and in enterprises; the share still unpatched is unknown)
CVE-2018-0802
Memory Corruption RCE in Microsoft Office Equation Editor

A memory-corruption flaw (out-of-bounds write, CWE-787) in the legacy Equation Editor component (EQNEDT32.EXE) shipped with Microsoft Office 2007, 2010, 2013, and 2016 allows remote code execution due to improper handling of objects in memory. An attacker triggers it by persuading a user to open a specially crafted document (for example an RTF or DOCX containing a malformed embedded equation object), causing the Equation Editor process to corrupt memory when the file is opened in Word; the user-interaction requirement is reflected in the CVSS 3.1 vector (AV:L/UI:R). Successful exploitation gives the attacker code execution in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8, High). Any user of the affected Office versions, the Office Compatibility Pack, or Word on an unpatched system is affected. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, carries a 93.3% EPSS probability of exploitation within 30 days, and multiple public analyses and proof-of-concepts exist.

Do: Apply Microsoft's January 2018 security updates for Office 2007, 2010, 2013, and 2016 and the Office Compatibility Pack, and verify the legacy Equation Editor executable (EQNEDT32.EXE) on endpoints has been patched or removed (Microsoft later retired the component). Because the flaw is exploited in the wild and used in ransomware campaigns, prioritize remediation per CISA KEV required action and hunt for Word spawning EQNEDT32.EXE or unexpected child processes when documents are opened. Until patched, open untrusted documents in Protected View and treat email-delivered RTF/DOCX attachments as untrusted.

7.893% KEV ransomware PoC ×3
  • Microsoft Office Office 2007, Office 2010, Office 2013, Office 2016 (Equation Editor component)
  • Microsoft Office Compatibility Pack
  • Microsoft Word
masshundreds of millions of Office users at time of disclosure (vulnerable Equation Editor shipped by default with Office 2007-2016); largely patched today, with…
Full article649 words · extracted from securityaffairs.com · click to collapse

Cloud Atlas threat actors used a new piece of polymorphic malware in recent attacks against government organizations.

The Cloud Atlas cyberespionage group, aka Inception, continues to carry out attacks against government organizations and was observed using a new piece of polymorphic malware dubbed VBShower.

The Cloud Atlas was first observed by researchers at Kaspersky Lab back in 2014, at the time the group was targeting government, diplomatic and research organizations. The campaign was dubbed by Kaspersky the return of Red October because the attackers targeted the same organizations of the previous campaign.

“From the beginning of 2019 until July, we have been able to identify different spear-phishing campaigns related to this threat actor mostly focused on Russia, Central Asia and regions of Ukraine with ongoing military conflicts.” reads the report published by Kaspersky Lab.

“Cloud Atlas hasn’t changed its TTPs (Tactic Tools and Procedures) since 2018 and is still relying on its effective existing tactics and malware in order to compromise high value targets.”

Most of the victims of the group were located in Russia, followed by Kazakhstan, Belarus, India and the Czech Republic. Over the year the group also targeted entitied in Ukraine, Moldova, Belgium, Iran, France, the United States, Turkey, Georgia, and Bulgaria.

Now the group continues to be mainly focused on Russia, but other victims were reported by Kaspersky in Kyrgyzstan, Turkmenistan, Ukraine, Turkey, Romania and Portugal. Most of the victims belong to government organizations, but researchers observed that attacks against Russian entities hit religious organizations, the aerospace industry and an international organization.

The Cloud Atlas attacks still leverage spear-phishing messages to target high profile victims. These emails are crafted with Office documents that use malicious remote templates that were hosted on remote servers.

In past attacks, Cloud Atlas was delivering a “validator” implant tracked as “PowerShower” by chaining the CVE-2017-11882 and the CVE-2018-0802 issues. Recently Kaspersky has observed the threat actor adopting a new infection chain, involving a polymorphic HTA, a new and polymorphic VBS implant used to deliver the PowerShower, and a second stage modular backdoor that we first detected five years ago.

The threat actors were using the PowerShower malware since October 2018. The malicious code allows fetching PowerShell and VBS modules that can be executed on a compromised machine to gather intelligence and exfiltrate data.

Since April 2019, Kaspersky researchers have observed the Cloud Atlas group using a new piece of malware tracked as VBShower in a new “polymorphic” infection chain. Cloud Atlas attackers were using a polymorphic HTA hosted on a remote server, which is used to drop the following different files on the local system:

  • A backdoor tracked as VBShower which is polymorphic and replaces PowerShower as a validator;
  • A tiny launcher for VBShower ;
  • A file computed by the HTA which contains contextual data such as the current user, domain, computer name and a list of active processes.

The “polymorphic” infection chain allows evading detection based on IoCs. Experts pointed out that each code is unique by victim.

cloud atlas

“The VBShower backdoor has the same philosophy of the validator version of PowerShower. Its aim is to complicate forensic analysis by trying to delete all the files contained in “%APPDATA%\..\Local\Temporary Internet Files\Content.Word” and “%APPDATA%\..\Local Settings\Temporary Internet Files\Content.Word\”. ” continues the analysis.

Kaspersky confirmed that Cloud Atlas attackers appeared to be Russian-speaking, but the security firm did not link it with any government.

“Cloud Atlas remains very prolific in Eastern Europe and Central Asia. The actor’s massive spear-phishing campaigns continue to use its simple but effective methods in order to compromise its targets.” concluded Kaspersky.

“Unlike many other intrusion sets, Cloud Atlas hasn’t chosen to use open source implants during its recent campaigns, in order to be less discriminating. More interestingly, this intrusion set hasn’t changed its modular backdoor, even five years after its discovery.”

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – CloudAtlas, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/89788/malware/cloud-atlas-recent-activity.html