Central Tibetan Administration Website Compromised
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2012-4681 | Remote Code Execution in Oracle Java SE Runtime Environment (JRE) A vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE allows arbitrary code execution remotely. It is triggered when the JRE processes attacker-controlled input, letting the attacker run arbitrary code in the context of the affected Java process. Any system running an affected Oracle Java SE build is exposed, including desktops and servers where Java is installed or used. Exploitation is confirmed in the wild: the flaw was weaponized by exploit kits in 2012 (e.g., the Whitehole Exploit Kit, whose use in the wild coincided with this CVE's coverage), was added to CISA's KEV on 2022-03-03 with known ransomware use, and EPSS currently assigns a 98.5% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is catalogued in this data, but the flaw should be treated as actively exploited and urgent to patch. Do: Inventory all systems running Oracle Java SE and apply updates per vendor instructions, as CISA's required action specifies. Where immediate patching is not possible, disable or restrict the Java browser plug-in and limit Java execution to trusted sites, since the flaw was historically exploited via drive-by exploit kits. Given the KEV listing and 98.5% EPSS score, prioritize patching internet-exposed and ransomware-relevant systems. | — | 99% | KEV ransomware |
| massOrder of hundreds of millions of installations/endpoints (well above 1M); precise current count unknown from this data | |
| CVE-2013-2423 | Remote Integrity-Affecting Vulnerability in Oracle JRE HotSpot (CVE-2013-2423) An unspecified vulnerability in the HotSpot component of Oracle's Java Runtime Environment (JRE) can be triggered remotely, allowing attackers to affect the integrity of the affected system. Oracle did not publish technical detail for the flaw, so defenders should treat unpatched legacy JRE deployments as potentially exposed without being able to precisely scope the trigger. An attacker who successfully exploits it gains the ability to tamper with the target's integrity; related reporting around the LightsOut Exploit Kit and compromised websites suggests Java flaws of this era were used in drive-by web attacks. Any endpoint or server running an unpatched Oracle JRE is affected, with legacy Java installations that never received current updates being the most likely remaining targets. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25, and EPSS assigns it an 85.3% probability of exploitation within 30 days (100th percentile), though no public proof-of-concept is catalogued and ransomware use is unknown. Do: Apply Oracle's Java updates immediately per CISA's required action: upgrade all JRE installations to a currently supported release, at minimum incorporating the April 2013 Oracle Critical Patch Update that addressed this flaw. Inventory endpoints and servers for legacy JRE installs, remove or disable the Java browser plugin where it is not required, and watch for drive-by exploit kit activity (e.g., LightsOut) as an indicator of exposure. | — | 85% | KEV |
| masshundreds of millions of endpoints (Java's historical install base), of which the remaining unpatched legacy subset is likely tens of thousands to millions of… |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 59.188.239.46 | orrect. The related C2 is located at news.worldlinking.com (59.188.239.46). This threat actor has been quietly operating these sorts |
| md5 | a6d7edc77e745a91b1fc6be985994c6a | ell. That file is a 397 kb win32 executable “aMCBlHPl.exe” (a6d7edc77e745a91b1fc6be985994c6a) detected as “Trojan.Win32.Swisyn.cyxf”. Backdoors detected |
| md5 | edd8b301eeb083e9fdf0ae3a9bdb3cd6 | . The Java exploit being delivered is the 212kb “YPVo.jar” (edd8b301eeb083e9fdf0ae3a9bdb3cd6), which archives, drops and executes the backdoor as well. |
Full article609 words · extracted from securelist.com · click to collapse
A snippet of code on the Central Tibetan Administration website redirects CN speaking visitors to a Java exploit that drops an APT-related backdoor. For some context, the site claims the administration itself as “…the Central Tibetan Administration (CTA) of His Holiness the Dalai Lama, this is the continuation of the government of independent Tibet.” The selection of placement for the malicious code is fairly extraordinary, so let’s dive in.
The attack itself is precisely targeted, as an appended, embedded iframe redirects “xizang-zhiye(dot)org” visitors (this is the CN-translated version of the site) to a java exploit that maintains a backdoor payload. The english and Tibetan versions of the website do not maintain this embedded iframe on the Chinese version (please do not visit at this time). At this point in time, it seems that the few systems attacked with this code are located in China and the US, although there could be more. The Java exploit being delivered is the 212kb “YPVo.jar” (edd8b301eeb083e9fdf0ae3a9bdb3cd6), which archives, drops and executes the backdoor as well. That file is a 397 kb win32 executable “aMCBlHPl.exe” (a6d7edc77e745a91b1fc6be985994c6a) detected as “Trojan.Win32.Swisyn.cyxf”. Backdoors detected with the Swisyn verdict are frequently a part of APT related toolchains, and this one most certainly is.
The Java exploit appears to attack the older CVE-2012-4681 vulnerability, which is a bit of a surprise, but it was used by the actor distributing the original CVE-2012-4681 0day Gondzz.class and Gondvv.class in August of last year. You can see the 4681 exploit code in the image above along with code setting the jvm SecurityManager to null to disable Java’s policy checks and then running the Payload.main method. The Payload.main method contains some interesting but simple capabilities that enable an attacker to download the payload over https and AES decrypt it using Java’s built-in AES crypto libraries, but the package is not configured to use that code in this case. Instead, a couple of lines in its configuration file direct the exploit to drop and execute the jar file’s win32 exe resource. The backdoor itself is detected by most of the AV crowd as variants of gaming password stealers, which is flatly incorrect. The related C2 is located at news.worldlinking.com (59.188.239.46).
This threat actor has been quietly operating these sorts of watering hole attacks for at least a couple of years and also the standard spearphishing campaigns against a variety of targets that include Tibetan groups. Our KSN community recorded related events going back to at least a busy late 2011 season. We also show Apple related Java exploits from this server targeting the more recent CVE-2013-2423.
UPDATE 2013.08.13: The CN version of the site at “xizang-zhiye(dot)org” appears to be cleaned up and has not been serving any malicious code that I can find over the past day. The administrators appear to have cleaned everything up on early Tuesday their time/later Monday “western” time and there are no indications of any return since. We will continue to monitor the site for signs of compromise.

Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/central-tibetan-administration-website-strategically-compromised/57476/