ZeroHour
CyberScooppublished ()ingested @AJVicens

North Korean hackers exploit Itaewon tragedy to infiltrate South Korean targets

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-41128

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-41128
Out-of-bounds Write RCE in Microsoft Windows JScript9 Scripting Engine

CVE-2022-41128 is a remote code execution flaw in the JScript9 scripting language on Microsoft Windows, classed by the CWE taxonomy as an out-of-bounds write (CWE-787), meaning crafted input can write past the end of an allocated memory buffer. Microsoft's description is limited, but flaws of this type in scripting engines are typically triggered when the engine processes attacker-crafted script content, such as script embedded in a web page or document. Successful exploitation would let an attacker execute arbitrary code in the context of the affected process on the target Windows system. Any Windows deployment that processes content through the JScript9 engine is affected, which spans a broad share of the Windows installed base. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-11-08, indicating confirmed in-the-wild exploitation; no public proof-of-concept is known, EPSS puts the 30-day exploitation probability at 24.6% (98th percentile), and ransomware use is unknown.

Do: Apply Microsoft's Windows security updates per vendor instructions without delay, prioritizing internet-facing and user-workstation systems because the flaw is KEV-listed as actively exploited. Until patched, limit exposure to untrusted script-bearing web content and documents from unverified sources, and verify remediation status against Microsoft's update guidance.

8.825% KEV
  • Microsoft Windows
mass≈1 billion+ Windows devices (order of magnitude; the engine ships with Windows itself)
Full article550 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The notorious hacking group used the Halloween tragedy that killed more than 150 people to trick South Koreans into downloading malware.

Mourners pay tributes at a makeshift memorial for the victims of the deadly Halloween crowd surge, outside a subway station in the district of Itaewon in Seoul on November 1, 2022. (Photo by JUNG YEON-JE/AFP via Getty Images)

A North Korean hacking group took advantage of the Oct. 29 Itaewon crowd-crush tragedy, which killed more than 150 people, to trick South Korean targets into downloading malicious files, researchers with Google’s Threat Analysis Group revealed Wednesday.

The discovery of the campaign appears to be just the latest attempt by a notorious North Korean hacking group known as APT37, which has targeted North Korean defectors, policymakers, journalists and human rights activists and others in South Korea for the past decade.

Researchers discovered the campaign after multiple South Korean submissions of a Microsoft Office document titled “221031 Seoul Yongsan Itaewon accident response situation (06:00)” to VirusTotal on Oct. 31.

The hackers appear to have designed the malicious document to install malware on victims’ devices and relied on a recently discovered Internet Explorer zero-day vulnerability, CVE-2022-41128, that allows for remote code execution.

Researchers notified Microsoft about the zero-day within a few hours of its discovery Oct. 31 and patches were issued on Nov. 8.

Google researchers did not recover a final payload associated with this campaign. The hacking group they believe is behind the campaign previously used implants known as ROKRAT, BLUELIGHT and DOLPHIN. “APT37 implants typically abuse legitimate cloud services as a [command and control] channel and offer capabilities typical of most backdoors,” the researchers said.

APT37 has previously used browser-based exploits to go after targets, the researchers noted.

“TAG is committed to sharing research to raise awareness on bad actors like APT37 within the security community, and for companies and individuals that may be targeted,” the researchers said. “By improving understanding of the tactics and techniques of these types of actors, we hope to strengthen protections across the ecosystem.”

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/north-korean-hackers-itaewon-tragedy/