Leaked Hacking Team tools were used by group stealing East Asian IP
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2015-5119 | Use-After-Free RCE in Adobe Flash Player (ActionScript 3 ByteArray) CVE-2015-5119 is a use-after-free memory-corruption vulnerability (CWE-119) in the ActionScript 3 ByteArray class of Adobe Flash Player. It is triggered when Flash processes crafted ActionScript/SWF content — typically a malicious .swf loaded from a web page, advertisement, email attachment, or document — causing Flash to access already-freed memory in an attacker-controllable way. A successful attack gives the adversary remote code execution in the context of the user running Flash. Anyone with Adobe Flash Player installed was exposed; at disclosure Flash was on the vast majority of internet-connected desktops, and today risk is concentrated in legacy browsers, office/document tooling, industrial or enterprise applications, and other systems where Flash was never removed. Exploitation status: this flaw has long-standing in-the-wild use (related headlines tie the leaked Hacking Team Flash exploit to APT campaigns against Japanese, East Asian, and US Government targets and to top 2016 exploit kits), it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS assigns a 99.3% probability of exploitation within 30 days. Do: Because Flash Player is end-of-life, CISA's required action is to disconnect it rather than patch: audit browsers, document/office tooling, and legacy or industrial applications for Flash dependencies and fully uninstall or disable Flash and any embedded SWF players. If a system must keep Flash temporarily, verify it runs a patched build from 2015 or later (Adobe's July 2015 emergency update, APSB15-16, addressed this flaw) and block untrusted SWF content via browser settings, email gateway, and web filtering. Prioritize cleanup on internet-facing endpoints and users who browse the web or open untrusted email attachments, the typical delivery route for this exploit. | — | 99% | KEV |
| mass≈ millions of legacy desktop installations | |
| CVE-2017-0199 | Remote Code Execution in Microsoft Office and WordPad via crafted document files CVE-2017-0199 is a remote code execution vulnerability in Microsoft Office and WordPad that stems from improper parsing of specially crafted files. Attackers trigger it by getting a user to open a malicious document, after which attacker-controlled code executes with the privileges of the logged-in user. Anyone running the affected Microsoft Office or WordPad software is exposed, and CISA notes the flaw has been leveraged in ransomware campaigns; no CVSS score is available in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), indicating active, ongoing exploitation. Do: Apply Microsoft's security updates for Office and Windows per vendor instructions, as required by CISA's KEV catalog; the flaw was publicly reported as fixed in Microsoft's April 2017 security updates. Until patched, treat unsolicited Office documents and email attachments as high-risk, since exploitation requires a user to open a crafted file. Verify that all Office and WordPad installations across the estate—especially endpoints that handle untrusted documents—have received the update. | 7.8 | 100% | KEV ransomware PoC ×6 |
| masshundreds of millions of Office installations worldwide (exact count unknown) |
Full article824 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A sophisticated and "well-funded" hacking group with a penchant for stealing intellectual property and other trade secrets is wreaking havoc in East Asia.
A sophisticated and “well-funded” hacking group with a penchant for stealing intellectual property and other trade secrets is wreaking havoc in East Asia by exploiting a series of old, publicly acknowledged software vulnerabilities, according to research conducted by TrendMicro.
The findings are significant because it exposes an active regional threat that continues to invest in new hacking capabilities — including unique backdoor implants and an exfiltration tools — while apparently running multiple, active economic espionage operations.
Dubbed “BlackTech” by security reachers, the clandestine unit is believed to be associated with three separate campaigns dating back to at least 2010. During that time frame, BlackTech relied on a similar server infrastructure to launch attacks but used various different tools and techniques against organizations, allowing them to move laterally across victim networks and ultimately attempt to exfiltrate sensitives files.
“We are confident attributing these three campaigns to BlackTech given the backend infrastructure used and target overlap,” said Trend Micro Vice President Mark Nunnikhoven. “The backend infrastructure — where the stolen data is sent — is unique to these campaigns and it is extremely rare that unrelated criminals groups share infrastructure for targeted attacks.”
BlackTech has in the past used an exploit for a Adobe Flash vulnerability (CVE-2015-5119) that was leaked during the Hacking Team breach. In addition, the group was seen taking advantage of outdated software flaws, all of which have already been patched, in older versions of Microsoft Windows, including the now infamous CVE-2017-0199.
CVE-0199 has become especially popular in recent months amongst cybercrime groups looking for an opening to plant ransomware on a server or computer.
“The ulterior motive of [BlackTech] is to steal important documents from their victims; initial recipients of their attacks are not always their primary target,” Trend Micro’s report reads. “We saw several decoy documents stolen by the attackers that are then used against another target. This indicates that document theft is most likely the first phase of an attack chain against a victim with ties to the intended target.”
Researchers found digital forensic evidence that BlackTech had worked to compromise a variety of companies and organizations, including “privatized agencies and government contractors as well as enterprises in the consumer electronics, computer, healthcare and financial industries,” particularly those based in Taiwan and occasionally in Japan and Hong Kong.
“We’re seeing a continued investment by this group to keep their malware relevant,” said Nunnikhoven. “That’s a strong indicator that this group is having some measure of success.”
He added, “running concurrent targeted campaigns using a variety of techniques takes a lot of effort. That effort would be better spent on other cybercrimes if they weren’t getting what they are after.”
BlackTech is known to send phishing emails that contain malicious Microsoft Word document attachments to the employees of targeted organizations. When opened, the attachment calls out to the attacker’s command and control infrastructure, allowing for the hackers to upload malware.
Experts say that competitive economic espionage, empowered by cyber means, has become common in the East Asia region. Countries like Vietnam are believed to be heavily investing in developing hacking capabilities.
Although the group uncovered by Trend Micro appears to be similar in some respects to another threat actor named “APT12,” revealed by U.S. cybersecurity firm FireEye, Nunnikhoven said there is no definitive proof to confidently link the two entities.
“We currently have no evidence that ties BlackTech to APT12. While there is some similarity in the targets and techniques, there isn’t enough data to draw a link between the two groups,” he said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/hacking-team-black-tech-trend-micro-ip-theft/