Panda Emissary APT specialized in defence aerospace projects
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2010-0738 | Authentication Bypass via HTTP Verb Tampering in Red Hat JBoss JMX-Console Red Hat JBoss Enterprise Application Platform's JMX-Console web application enforces its access-control checks only for the HTTP GET and POST methods, leaving requests sent with other HTTP verbs unauthenticated. A remote attacker can reach the console's GET handler by submitting the same request with a different method (e.g., HEAD), bypassing the configured authentication and access controls entirely. Once past the access control, the attacker can interact with the JMX console's management interfaces, a foothold that on many deployments can be escalated toward broader compromise of the JBoss server. Any organization running Red Hat JBoss (JBoss AS / JBoss EAP) where the JMX-Console is reachable, whether internally or exposed to the internet, is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25) with known ransomware use, and EPSS assigns a 79.4% probability of exploitation within 30 days, so active exploitation should be assumed. Do: Apply updates per Red Hat's vendor instructions, as required by CISA's KEV catalog. Until patched, restrict network access to the JMX-Console and block HTTP methods other than GET and POST (e.g., at a reverse proxy or in the application's security constraints) so the access-control check cannot be bypassed with verbs like HEAD, and review logs for requests to /jmx-console using unusual methods. Treat this flaw as actively exploited given its KEV listing with known ransomware use. | — | 79% | KEV ransomware |
| largeTens of thousands of JBoss server installations plausibly affected (order of magnitude 10,000-100,000 systems) | |
| CVE-2011-3544 | Remote Code Execution in Oracle Java SE JRE Applet Rhino Script Engine CVE-2011-3544 is an access control flaw in the Rhino JavaScript Script Engine component used by Java applets in Oracle's Java Runtime Environment. It is triggered when a user's browser loads a malicious Java applet, allowing script executed through the Rhino engine to bypass Java's access restrictions. An attacker who successfully exploits it gains the ability to run arbitrary code on the victim's machine with the privileges of the logged-in user, typically via drive-by download from a compromised or attacker-controlled website. Any system with a vulnerable Oracle Java SE JDK or JRE and an enabled Java browser plugin is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-03-03, carries a 96.7% EPSS probability of exploitation within 30 days, and contemporary reports show it weaponized in the BlackHole/Whitehole exploit kits and used in mass OS X exploitation. Do: Apply updated Oracle Java SE builds per Oracle's vendor instructions, prioritizing internet-facing and end-user systems listed in the KEV guidance. Where patching is delayed, disable the Java browser plugin or block Java applets at the web gateway, since the attack vector is malicious applets served over the web. Review endpoints for signs of exploit-kit drive-by compromise, especially legacy Windows and OS X machines with outdated Java. | — | 97% | KEV |
| masshundreds of millions of desktops and servers with a Java runtime installed; exact count unknown |
Full article684 words · extracted from securityaffairs.com · click to collapse

The Panda Emissary group extensively uses long-running strategic web compromises and relies on whitelists to syphon defence aerospace projects from victims.
An alleged Chinese APT group dubbed Panda Emissary (also known as TG-3390) is targeting high-profile governments and organisations searching for defense aerospace projects.
Researchers at Dell discovered that the Panda Emissary group used Watering hole attacks as the attack vector, the APT group it likes to compromise websites popular with a target organisation’s personnel.
“The group extensively uses long-running [watering holes], and relies on whitelists to deliver payloads to select victims,” Dell’s counter-threat unit wrote in a report.”
The group exploits old vulnerabilities which aren’t yet patched by victims, researchers at Dell observed that the group mainly exploited Java flaws, including CVE-2011-3544 and CVE-2010-0738.
According to the experts, the Panda Emissary group has already compromised more than 100 websites. It is interesting to note that watering holes used by the hackers include a whitelist to run surgical attacks by ensuring that only staff from a target organisation are infected remaining under the radar for a long time.
Another peculiarity of the Panda Emissary group is the use of custom Microsoft Exchange backdoors and credential logger. The Panda Emissary used custom tools OwaAuth web shell and ASPXTool, and also popular criminal hacking tools PlugX RAT, HttpBrowser, and China Chopper.
“After the initial compromise, TG-3390 delivers the HttpBrowser backdoor to its victims. The threat actors then move quickly to compromise Microsoft Exchange servers and to gain complete control of the target environment.” “The threat actors are adept at identifying key data stores and selectively exfiltrating all of the high-value information associated with their goal.”
“The group extensively uses long-running strategic web compromises (SWCs), and relies on whitelists to deliver payloads to select victims. In comparison to other threat groups, TG-3390 is notable for its tendency to compromise Microsoft Exchange servers using a custom backdoor and credential logger.”
The Panda Emissary group targeted large manufacturing companies supplying defense organizations, energy firms, embassies in Washington, DC representing countries in the Middle East, Europe, and Asia, NGOs particularly focused on international relations and defense and of course government organizations.
“CTU researchers have discovered numerous details about TG-3390 operations, including how the adversaries explore a network, move laterally, and exfiltrate data. As shown in Figure 11, after compromising an initial victim’s system (patient 0), the threat actors use the Baidu search engine to search for the victim’s organization name. They then identify the Exchange server and attempt to install the OwaAuth web shell. If the OwaAuth web shell is ineffective because the victim uses two-factor authentication for webmail, the adversaries identify other externally accessible servers and deploy ChinaChopper web shells. Within six hours of entering the environment, the threat actors compromised multiple systems and stole credentials for the entire domain.”
The hackers belonging to the Panda Emissary group only syphon data related to specific U.S. defense projects, the report doesn’t s provide further information on the motivation behind the attacks. It is not clear if the hacking crew is state-sponsored team or a hacking-for-hire group.
“CTU researchers have observed the threat group obtaining information about specific U.S. defense projects that would be desirable to those operating within a country with a manufacturing base, an interest in U.S. military capability, or both,” states Dell. “The adversary’s end goal is to exfiltrate, not infiltrate. After gaining access to a target network in one intrusion analysed by CTU researchers, TG-3390 actors identified and exfiltrated data for specific projects run by the target organisation.”
It also has access to a criminal development team focused on building hacking tools and is proficient at hiding malware and does not bother with reconnaissance, instead of waiting to gain a foothold in target organisations.
Researchers from Dell speculate on the Chinese origin of the hacking team, they observed local working hours and the use of native language tools, but they cannot exclude that this information could be the result of a false-flag operation.
Enjoy the report.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(Security Affairs – Panda Emissary, cyber espionage)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/39154/cyber-crime/panda-emissary-apt.html