ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Water Hydra’s Zero-Day Attack Chain Targets Financial Traders

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-38831
Code Execution in RARLAB WinRAR via Crafted ZIP File/Folder Name Confusion

RARLAB WinRAR before 6.23 mishandles ZIP archives that contain a benign file (such as a JPG) alongside a folder with the same name, causing the folder's contents - which can include malicious executable files - to be processed when the user merely attempts to view the benign file. By sending a crafted ZIP archive, an attacker gains arbitrary code execution on the victim's machine with the user's privileges. Because the flaw is local (AV:L) and requires user interaction, risk is limited to Windows systems running an unpatched copy of WinRAR, while machines without the tool are unaffected. The bug was actively exploited in the wild from April through October 2023, including by government-backed actors (APT28), SideCopy attacks on Indian government entities, ransomware operations, and trading-account theft campaigns, and it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-08-24.

Do: Upgrade all Windows systems running WinRAR to version 6.23 or later, which fixes this flaw; if patching is not immediately possible, treat ZIP files from untrusted sources with caution and check archives for duplicate file/folder names before opening. Given KEV listing with known ransomware use and public proof-of-concept exploits, hunt for compromise by reviewing whether unexpected executables or scripts ran when ZIP archives were opened, and apply vendor mitigations per CISA's required action or discontinue use if mitigations are unavailable.

7.898% KEV ransomware PoC ×4
  • RARLAB WinRAR before 6.23
masshundreds of millions of users/installations worldwide (WinRAR is one of the most widely installed Windows archive utilities)
CVE-2024-21412
CVE-2024-21412: Security Feature Bypass in Microsoft Windows Internet Shortcut Files

CVE-2024-21412 is a security feature bypass (CWE-693) in how Microsoft Windows handles Internet Shortcut files: a crafted shortcut can make Windows skip the security warning prompt that normally appears before untrusted internet content is opened or downloaded. Triggering it requires user interaction — an attacker must deliver a malicious shortcut file, typically via email or a malicious website, and convince the user to open it, which is reflected in the CVSS vector's UI:R component. An attacker who succeeds gains a bypass of those prompts, making it easier to retrieve and execute malicious remote content with fewer warnings; the DarkGate malware operators used exactly this technique in zero-day campaigns to distribute their loader. Anyone running the affected Windows 10 (1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), Windows Server 2019, or Windows Server 2022 (including 23H2) builds was exposed. The flaw was patched in Microsoft's February 2024 Patch Tuesday release (2024-02-13), the same day CISA added it to the KEV catalog, and it is under active exploitation with known ransomware association and a 95.4% EPSS score.

Do: Apply the February 2024 Windows cumulative security update (released 2024-02-13) or any later monthly cumulative update to every affected Windows 10, Windows 11, Windows Server 2019, and Windows Server 2022 build, and verify patch levels through your endpoint inventory. Because exploitation requires user interaction, as an interim control flag or block .url/Internet Shortcut attachments at email gateways and remind users not to open shortcuts from untrusted sources. Prioritize internet-facing and shared endpoints given the KEV listing and known ransomware use.

8.195% KEV ransomware
  • microsoft Windows 10 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2, 23H2
  • microsoft Windows Server 2019 all supported editions
  • +1 more
mass≈1 billion Windows 10/11/Server installations potentially affected worldwide (pre-patch installed base)
Full article332 words · extracted from infosecurity-magazine.com · click to collapse

The Trend Micro Zero Day Initiative (ZDI) has recently unearthed a critical vulnerability, identified as CVE-2024-21412, which they’ve dubbed ZDI-CAN-23100. 

The flaw was reported to Microsoft as part of a Microsoft Defender SmartScreen bypass utilized in a complex zero-day attack chain orchestrated by the APT group known as Water Hydra (AKA DarkCasino). Their targets were financial market traders.

Beginning in late December 2023, Trend Micro observed a campaign by Water Hydra employing similar tools, tactics and procedures (TTPs) that involved exploiting internet shortcuts (.URL) and Web-based Distributed Authoring and Versioning (WebDAV) components. 

In this attack, CVE-2024-21412 was used to evade Microsoft Defender SmartScreen and implant victims with the DarkMe malware. Through collaboration with Microsoft, the ZDI bug bounty program ensured swift disclosure and patching of this vulnerability.

Read more about this patch: Microsoft Fixes Two Zero-Days in February Patch Tuesday

The Water Hydra group, initially mistaken for the Evilnum APT group due to similarities in phishing techniques, has been active since 2021, primarily targeting the financial industry. Notably, they’ve exploited vulnerabilities such as CVE-2023-38831 and have showcased a high level of technical sophistication.

The Water Hydra attack chain, unveiled by Trend Micro in an advisory published on Tuesday, involves intricate methods to lure victims, including spear-phishing campaigns on forex and stock trading forums. They exploit the “search: protocol” to manipulate Windows Explorer views and deceive users into clicking malicious internet shortcut files.

Further analysis revealed that Water Hydra leveraged CVE-2024-21412 to bypass Microsoft Defender SmartScreen. By employing a cascade of internet shortcuts, they evaded security measures and executed malicious payloads, such as the DarkMe malware, without users’ knowledge.

According to Trend Micro, Water Hydra’s modus operandi underscores the severity of zero-day threats in cybersecurity. 

“When faced with uncertain intrusions, behaviors and routines, organizations should assume that their system is already compromised or breached and work to immediately isolate affected data or toolchains,” reads the advisory.

“With a broader perspective and rapid response, organizations can address breaches and protect their remaining systems.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/water-hydras-zero-day-financial/