North Korean hackers exploit Itaewon tragedy to infiltrate South Korean targets
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-41128 | Out-of-bounds Write RCE in Microsoft Windows JScript9 Scripting Engine CVE-2022-41128 is a remote code execution flaw in the JScript9 scripting language on Microsoft Windows, classed by the CWE taxonomy as an out-of-bounds write (CWE-787), meaning crafted input can write past the end of an allocated memory buffer. Microsoft's description is limited, but flaws of this type in scripting engines are typically triggered when the engine processes attacker-crafted script content, such as script embedded in a web page or document. Successful exploitation would let an attacker execute arbitrary code in the context of the affected process on the target Windows system. Any Windows deployment that processes content through the JScript9 engine is affected, which spans a broad share of the Windows installed base. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-11-08, indicating confirmed in-the-wild exploitation; no public proof-of-concept is known, EPSS puts the 30-day exploitation probability at 24.6% (98th percentile), and ransomware use is unknown. Do: Apply Microsoft's Windows security updates per vendor instructions without delay, prioritizing internet-facing and user-workstation systems because the flaw is KEV-listed as actively exploited. Until patched, limit exposure to untrusted script-bearing web content and documents from unverified sources, and verify remediation status against Microsoft's update guidance. | 8.8 | 25% | KEV |
| mass≈1 billion+ Windows devices (order of magnitude; the engine ships with Windows itself) |
Full article550 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The notorious hacking group used the Halloween tragedy that killed more than 150 people to trick South Koreans into downloading malware.
A North Korean hacking group took advantage of the Oct. 29 Itaewon crowd-crush tragedy, which killed more than 150 people, to trick South Korean targets into downloading malicious files, researchers with Google’s Threat Analysis Group revealed Wednesday.
The discovery of the campaign appears to be just the latest attempt by a notorious North Korean hacking group known as APT37, which has targeted North Korean defectors, policymakers, journalists and human rights activists and others in South Korea for the past decade.
Researchers discovered the campaign after multiple South Korean submissions of a Microsoft Office document titled “221031 Seoul Yongsan Itaewon accident response situation (06:00)” to VirusTotal on Oct. 31.
The hackers appear to have designed the malicious document to install malware on victims’ devices and relied on a recently discovered Internet Explorer zero-day vulnerability, CVE-2022-41128, that allows for remote code execution.
Researchers notified Microsoft about the zero-day within a few hours of its discovery Oct. 31 and patches were issued on Nov. 8.
Google researchers did not recover a final payload associated with this campaign. The hacking group they believe is behind the campaign previously used implants known as ROKRAT, BLUELIGHT and DOLPHIN. “APT37 implants typically abuse legitimate cloud services as a [command and control] channel and offer capabilities typical of most backdoors,” the researchers said.
APT37 has previously used browser-based exploits to go after targets, the researchers noted.
“TAG is committed to sharing research to raise awareness on bad actors like APT37 within the security community, and for companies and individuals that may be targeted,” the researchers said. “By improving understanding of the tactics and techniques of these types of actors, we hope to strengthen protections across the ecosystem.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/north-korean-hackers-itaewon-tragedy/