Chinese APT41 Hackers Broke into at Least 6 U.S. State Governments: Mandiant
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44207 | Hard-Coded Credentials in Acclaim Systems USAHERDS (through 7.4.0.1) CVE-2021-44207 is a use of hard-coded credentials (CWE-798) in Acclaim Systems USAHERDS through version 7.4.0.1. Because built-in credentials are embedded in the application rather than provisioned per deployment, a remote attacker who learns or extracts them can authenticate to the system over the network with no privileges and no user interaction (CVSS 3.1: 8.1, high attack complexity). Successful abuse gives the attacker unauthorized authenticated access to USAHERDS and its data, providing a foothold in the hosting environment that has been used in active exploitation. Affected organizations are those running USAHERDS up to and including 7.4.0.1 — a niche government-sector web application rather than a mass-market product — so exposure is concentrated in a small number of agency deployments. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-12-23 citing active exploitation, and EPSS currently assigns a 17.6% probability of exploitation in the next 30 days (97th percentile). Do: Per the CISA KEV required action, apply mitigations per vendor instructions — contact Acclaim Systems for a supported fix or mitigation — or discontinue use of the product if mitigations are unavailable (federal agencies must act within two weeks of the 2024-12-23 KEV addition per BOD 22-01). In the meantime, restrict network exposure of USAHERDS to trusted users only and review authentication logs for unexpected logins, especially with built-in/service accounts, since the hard-coded credentials cannot be rotated by administrators alone. No public proof-of-concept is known, but active exploitation is confirmed, so treat any USAHERDS instance reachable from the internet as at risk. | 8.1 | 18% | KEV |
| nichelikely tens to low hundreds of deployments (estimated; no public install counts available) | |
| CVE-2021-44228 | JNDI Injection Remote Code Execution in Apache Log4j2 (Log4Shell) Apache Log4j2, an extremely widely used Java logging library, fails to protect its JNDI lookup feature against attacker-controlled JNDI-related endpoints (CWE-20, CWE-502), so crafted text processed by the logger causes the Java runtime to fetch and load attacker-supplied objects, leading to remote code execution. The flaw is triggered whenever attacker-controlled input reaches the logging API and is parsed for JNDI lookups, a pattern common in web servers and enterprise Java applications that log user-supplied fields such as headers or form values. Successful exploitation yields arbitrary code execution under the privileges of the affected application, giving attackers a foothold for lateral movement, data theft, and ransomware deployment. Any Java application or product that ships or bundles an affected Apache Log4j2 release is exposed, making this one of the most broadly deployed vulnerabilities ever disclosed. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-12-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days. Do: Inventory all Java applications and dependencies for Apache Log4j2 and apply the vendor's patched updates, or remove affected assets from the network, as required by CISA's KEV catalog. Where updates are not yet available, use the temporary mitigations in CISA's ED-22-02 recommended-mitigation guidance, such as disabling message lookups, only until patches are applied. Prioritize internet-facing and business-critical systems and hunt for exploitation activity given known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×9 |
| masshundreds of millions of Java applications/devices, with hundreds of thousands of internet-exposed services |
Full article673 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 09, 2022
APT41, the state-sponsored threat actor affiliated with China, breached at least six U.S. state government networks between May 2021 and February 2022 by retooling its attack vectors to take advantage of vulnerable internet-facing web applications.
The exploited vulnerabilities included "a zero-day vulnerability in the USAHERDS application (CVE-2021-44207) as well as the now infamous zero-day in Log4j (CVE-2021-44228)," researchers from Mandiant said in a report published Tuesday, calling it a "deliberate campaign."
Besides web compromises, the persistent attacks also involved the weaponization of exploits such as deserialization, SQL injection, and directory traversal vulnerabilities, the cybersecurity and incident response firm noted.
The prolific advanced persistent threat, also known by the monikers Barium and Winnti, has a track record of targeting organizations in both the public and private sectors to orchestrate espionage activity in parallel with financially motivated operations.
In early 2020, the group was linked to a global intrusion campaign that leveraged a variety of exploits involving Citrix NetScaler/ADC, Cisco routers, and Zoho ManageEngine Desktop Central to strike dozens of entities in 20 countries with malicious payloads.
The latest disclosure continues the trend of APT41 quickly co-opting newly disclosed vulnerabilities such as Log4Shell to gain initial access into target networks, counting that of two U.S. state governments and insurance and telecom firms, within hours of it becoming public knowledge.
The intrusions continued well into February 2022 when the hacking crew re-compromised two U.S. state government victims that were infiltrated for the first time in May and June 2021, "demonstrating their unceasing desire to access state government networks," the researchers said.
What's more, the foothold established after the exploitation of Log4Shell resulted in the deployment of a new variant of a modular C++ backdoor called KEYPLUG on Linux systems, but not before performing extensive reconnaissance and credential harvesting of the target environments.
Also observed during the attacks were an in-memory dropper called DUSTPAN (aka StealthVector) that's orchestrated to execute the next-stage payload, alongside advanced post-compromise tools like DEADEYE, a malware loader that's responsible for launching the LOWKEY implant.
Chief among the variety of techniques, evasion methods, and capabilities used by APT41 involved the "substantially increased" usage of Cloudflare services for command-and-control (C2) communications and data exfiltration, the researchers said.
Though Mandiant noted it found evidence of the adversaries exfiltrating personally identifiable information that's typically in line with an espionage operation, the ultimate goal of the campaign is currently unclear.
The findings also mark the second time a Chinese nation-state group has abused security flaws in the ubiquitous Apache Log4j library to penetrate targets.
In January 2022, Microsoft detailed an attack campaign mounted by Hafnium – the threat actor behind the widespread exploitation of Exchange Server flaws a year ago – that utilized the vulnerability to "attack virtualization infrastructure to extend their typical targeting."
If anything, the latest activities are yet another sign of a constantly adapting adversary that's capable of shifting its goalposts as well as refining its malware arsenal to strike entities around the world that are of strategic interest.
The threat actor's incessant operations against healthcare, high-tech, and telecommunications sectors over the years have since caught the attention of the U.S. Justice Department, which issued charges against five members of the group in 2020, landing the hackers a place on the FBI's cyber most wanted list.
"APT41 can quickly adapt their initial access techniques by re-compromising an environment through a different vector, or by rapidly operationalizing a fresh vulnerability," the researchers said. "The group also demonstrates a willingness to retool and deploy capabilities through new attack vectors as opposed to holding onto them for future use."
In a related development, Google's Threat Analysis Group said it took steps to block a phishing campaign staged by another Chinese state-backed group tracked as APT31 (aka Zirconium) last month that was aimed at "high profile Gmail users affiliated with the U.S. government."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/03/chinese-apt41-hackers-broke-into-at.html