ZeroHour
The Recordpublished ()ingested

FBI, NSA: Russian military cyber-unit behind large-scale brute

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0688
RCE in Microsoft Exchange Server from Shared Install-Time Validation Keys

CVE-2020-0688 is a remote code execution vulnerability in Microsoft Exchange Server caused by the validation key not being uniquely created at install time, leaving deployments with a predictable, shared key (CWE-287, improper authentication). A remote attacker who can reach an affected Exchange server and knows the common install-time key can supply maliciously crafted, cryptographically signed payloads that the server trusts, triggering code execution without needing per-server secrets. Successful exploitation gives the attacker code execution on the Exchange server, which can be used to access mail data, move laterally, and stage follow-on activity; CISA notes known use in ransomware campaigns. All organizations running the affected on-premises Microsoft Exchange Server are in scope per CISA's listing, though the affected version range is not specified in the source data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, and EPSS rates 30-day exploitation probability at 100% (top percentile).

Do: Apply Microsoft's Exchange security updates addressing CVE-2020-0688 (released in February 2020) to every on-premises Exchange server, per CISA's required action. As an interim mitigation, configure a unique ASP.NET machineKey in each Exchange server's web.config instead of the default shared install-time key, and hunt for indicators of exploitation given the known ransomware use.

8.8100% KEV ransomware PoC ×2
  • Microsoft Exchange Server
masshundreds of thousands of on-premises Exchange servers (≈500,000)
CVE-2020-17144
Remote Code Execution in Microsoft Exchange Server via Cmdlet Argument Validation

CVE-2020-17144 is a remote code execution vulnerability in Microsoft Exchange Server caused by improper validation of cmdlet arguments; the associated weakness class (CWE-502, deserialization of untrusted data) indicates that improperly validated attacker-supplied arguments are deserialized and executed by the server. An attacker triggers the flaw by sending specially crafted cmdlet arguments to a vulnerable Exchange server, causing attacker-controlled code to run on the server. Successful exploitation yields remote code execution on the Exchange host, which could provide command execution in the Exchange service context, access to mail data, and a foothold for further compromise. Organizations running affected on-premises Microsoft Exchange Server deployments are affected; the available data lists 'Microsoft Exchange Server' without specifying version ranges, and cloud-based Exchange Online is not implicated by this server-side flaw. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03, EPSS is high at 36.5% (98th percentile), no public PoC is known, and any association with ransomware is unknown.

Do: Inventory all on-premises Exchange servers and verify their current patch level, then apply Microsoft's Exchange security updates containing this fix (released in the November 2020 Patch Tuesday) per the CISA required action. Until patched, restrict access to Exchange management/cmdlet interfaces and review Exchange and PowerShell logs for unexpected cmdlet or deserialization activity. Given the confirmed in-the-wild exploitation (KEV) and elevated EPSS (36.5%), treat this as a high-priority patch even though no public PoC exists.

8.437% KEV
  • Microsoft Exchange Server
masshundreds of thousands of on-premises Exchange deployments worldwide
Full article566 words · extracted from therecord.media · click to collapse

US and UK cybersecurity agencies said today that a Russian military cyber unit has been behind a series of brute-force attacks that have targeted the cloud IT resources of government and private sector companies across the world.

The attacks have been linked to a hacking group tracked as APT28, or Fancy Bear, in a series of joint security advisories published today by the US National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), the US Federal Bureau of Investigation (FBI), and the UK's National Cyber Security Centre (NCSC).

Since at least mid-2019 through early 2021, Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS), military unit 26165, used a Kubernetes cluster to conduct widespread, distributed, and anonymized brute force access attempts against hundreds of government and private sector targets worldwide.
[...]
The 85th GTsSS directed a significant amount of this activity at organizations using Microsoft Office 365 cloud services; however, they also targeted other service providers and on-premises email servers using a variety of different protocols. These efforts are almost certainly still ongoing.

The four security agencies said that the brute-force attacks are only the beginning of an APT28 attack.

The agencies said the GRU hackers utilized the successfully compromised accounts to pivot internally inside the hacked organizations.

In particular, the agencies said that APT28 used the compromised account credentials in conjunction with exploits for Microsoft Exchange servers like CVE-2020-0688 and CVE-2020-17144, combining the two to gain access to internal email servers.

CISA, FBI, NSA, and NCSC officials said the group's attacks had remained largely under the radar because APT28 worked to disguise its brute-forcing attempts via the Tor network or commercial VPN services, such as CactusVPN, IPVanish, NordVPN, ProtonVPN, Surfshark, and WorldVPN.

These brute-force attacks were also carried out via a variety of protocols, such as HTTP(S), IMAP(S), POP3, and NTLM, so they weren't always coming via the same channels.

In addition, in a September 2020 report, Microsoft, which first discovered this new APT28 tactic, also added that while some attacks were carried out at scale, going after tens of thousands of accounts at more than 200 organizations, APT28 also took great care to distance the brute-force attempts far apart from each other and spread them across different IP address blocks, in order to prevent triggering anti-brute-force solutions.

The joint security advisory published today includes some of the IP addresses and user-agent strings used in these low-and-slow APT28 brute-force attacks that have been going on since 2019, so companies can deploy detections and countermeasures.

APT28 brute-force targets spread across multiple verticals

Per the four cybersecurity agencies, APT28's attacks have targeted the cloud resources of a wide array of targets, including government organizations, think tanks, defense contractors, energy companies, and more.

"This lengthy brute force campaign to collect and exfiltrate data, access credentials and more, is likely ongoing, on a global scale," Rob Joyce, NSA Director of Cybersecurity, said today.

"Net defenders should use multi-factor authentication and the additional mitigations in the advisory to counter this activity."

A downloadable PDF copy of the joint security advisory can be found here.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/fbi-nsa-russian-military-cyber-unit-behind-large-scale-brute-force-attacks