ZeroHour
Security Affairspublished ()ingested @securityaffairs

RomCom RAT attackers target groups supporting NATO membership of Ukraine

mediumMalwareimportance 35CVE-2022-30190

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-30190
MSDT URL Protocol Remote Code Execution in Microsoft Windows (Follina)

CVE-2022-30190 (Follina) is a remote code execution flaw in the Microsoft Windows Support Diagnostic Tool (MSDT) when MSDT is invoked through its ms-msdt URL protocol by a calling application such as Microsoft Word. Attackers trigger it by luring a user into opening a malicious document — typically a Word/RTF file whose link or remotely linked template launches the ms-msdt: URI with attacker-supplied commands — and CVSS 3.1 rates it 7.8 with a local attack vector and required user interaction. A successful exploit runs arbitrary code with the privileges of the calling application, allowing the attacker to install programs, view, change or delete data, or create new accounts in the user's context. Per the CISA data, affected platforms are Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 and 2012 — essentially any Windows installation that ships MSDT, with Office/Word as the common delivery vector. Exploitation is confirmed in the wild: Microsoft acknowledged it as an exploited zero-day, CISA added it to the KEV on 2022-06-14 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.2% (99th percentile), and contemporaneous reporting also tied its use to espionage actors including APT28.

Do: Apply Microsoft's security updates per vendor instructions (the fix shipped in the June 2022 Patch Tuesday releases for the affected Windows versions), as required by CISA's KEV. If patching must be delayed, follow Microsoft's documented mitigation to disable the MSDT URL protocol (remove or restrict the HKEY_CLASSES_ROOT\ms-msdt registry key) and enforce Office Protected View / block Word from fetching remote templates over the network. Hunt for exploitation by checking whether Office processes (WINWORD.exe) launch msdt.exe or sdiagnhost.exe, or whether ms-msdt: URIs are invoked unexpectedly.

7.899% KEV ransomware PoC
  • Microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows 7
  • +4 more
mass≈1 billion+ Windows devices (effectively the entire supported Windows installed base)

Indicators of compromiseAll →

TypeIndicatorContext
domainukrainianworldcongress.infoimate. Real Domain Fake Domain ukrainianworldcongress[.]org ukrainianworldcongress[.]info The cloned websites were spotted hosting weaponized versi
domainukrainianworldcongress.orgsuffix and make it look legitimate. Real Domain Fake Domain ukrainianworldcongress[.]org ukrainianworldcongress[.]info The cloned websites were sp
Full article442 words · extracted from securityaffairs.com · click to collapse

Threat actors are targeting NATO and groups supporting Ukraine in a spear-phishing campaign distributing the RomCom RAT.

On July 4, the BlackBerry Threat Research and Intelligence team uncovered a spear phishing campaign aimed at an organization supporting Ukraine abroad.

The researchers discovered two lure documents submitted from an IP address in Hungary, both targeting upcoming NATO Summit guests who are providing support to Ukraine.

The lure documents identified by BlackBerry impersonate Ukrainian World Congress, a legitimate non-profit, (“Overview_of_UWCs_UkraineInNATO_campaign.docx“) appear as a letter declaring support to the Ukrainian government for the inclusion to the NATO alliance (“Letter_NATO_Summit_Vilnius_2023_ENG(1).docx“).

The experts attributed the attacks to a threat actor known as RomCom (aka Tropical Scorpius and UNC2596) based on tactics, techniques, and procedures (TTPs), code similarity, and attack infrastructure.

The upcoming NATO Summit will be held in Vilnius on July 11-12, during the event, it will be discussed the possible future membership in the alliance of Ukraine.

Threat actors aimed at engaging the victims into clicking on a specially crafted replica of the Ukrainian World Congress website.

The attackers used typosquatting techniques to masquerade the fake website with a .info suffix and make it look legitimate.

Real DomainFake Domain
ukrainianworldcongress[.]orgukrainianworldcongress[.]info
RomCom RAT

The cloned websites were spotted hosting weaponized versions of popular software.

“Once the Microsoft Word file is downloaded and executed/opened by the user, an OLE object is loaded from the RTF, which connects to the IP address 104.234.239[.]26, which is related to VPN/proxies services. The connections are made to ports 80, 139, and 445 (HTTP and SMB services).” reads the report published by BlackBerry. “This file’s goal is to load the OLE streams into Microsoft Word, to render an iframe tag responsible for the execution of the next stage of malware.”

Upon opening the documents, a multi-stage attack chain is triggered, it also exploits the flaw CVE-2022-30190, aka known as Follina, affecting Microsoft’s Support Diagnostic Tool (MSDT).

The last stage malware is the RomCom RAT which is used by operators to collect information about the compromised system and execute remote commands.

“Based on the available information, we have medium to high confidence to conclude that this is a RomCom rebranded operation, or that one or more members of the RomCom threat group are behind this new campaign supporting a new threat group.” concludes the report. “The information we base this conclusion on includes: 

  • Geopolitical context
  • Domain’s registration and HTML scraping of legitimate websites
  • Certain similarities in the code between this campaign and previously known RomCom campaigns
  • Network infrastructure information”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, RomCom RAT)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/148324/intelligence/romcom-rat-groups-supporting-ukraine.html