ZeroHour
CyberScooppublished ()ingested @Bing_Chris

Leaked Hacking Team tools were used by group stealing East Asian IP

criticalRansomware exploited in the wildimportance 60CVE-2015-5119CVE-2017-0199

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-5119
Use-After-Free RCE in Adobe Flash Player (ActionScript 3 ByteArray)

CVE-2015-5119 is a use-after-free memory-corruption vulnerability (CWE-119) in the ActionScript 3 ByteArray class of Adobe Flash Player. It is triggered when Flash processes crafted ActionScript/SWF content — typically a malicious .swf loaded from a web page, advertisement, email attachment, or document — causing Flash to access already-freed memory in an attacker-controllable way. A successful attack gives the adversary remote code execution in the context of the user running Flash. Anyone with Adobe Flash Player installed was exposed; at disclosure Flash was on the vast majority of internet-connected desktops, and today risk is concentrated in legacy browsers, office/document tooling, industrial or enterprise applications, and other systems where Flash was never removed. Exploitation status: this flaw has long-standing in-the-wild use (related headlines tie the leaked Hacking Team Flash exploit to APT campaigns against Japanese, East Asian, and US Government targets and to top 2016 exploit kits), it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS assigns a 99.3% probability of exploitation within 30 days.

Do: Because Flash Player is end-of-life, CISA's required action is to disconnect it rather than patch: audit browsers, document/office tooling, and legacy or industrial applications for Flash dependencies and fully uninstall or disable Flash and any embedded SWF players. If a system must keep Flash temporarily, verify it runs a patched build from 2015 or later (Adobe's July 2015 emergency update, APSB15-16, addressed this flaw) and block untrusted SWF content via browser settings, email gateway, and web filtering. Prioritize cleanup on internet-facing endpoints and users who browse the web or open untrusted email attachments, the typical delivery route for this exploit.

99% KEV
  • Adobe Flash Player
mass≈ millions of legacy desktop installations
CVE-2017-0199
Remote Code Execution in Microsoft Office and WordPad via crafted document files

CVE-2017-0199 is a remote code execution vulnerability in Microsoft Office and WordPad that stems from improper parsing of specially crafted files. Attackers trigger it by getting a user to open a malicious document, after which attacker-controlled code executes with the privileges of the logged-in user. Anyone running the affected Microsoft Office or WordPad software is exposed, and CISA notes the flaw has been leveraged in ransomware campaigns; no CVSS score is available in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), indicating active, ongoing exploitation.

Do: Apply Microsoft's security updates for Office and Windows per vendor instructions, as required by CISA's KEV catalog; the flaw was publicly reported as fixed in Microsoft's April 2017 security updates. Until patched, treat unsolicited Office documents and email attachments as high-risk, since exploitation requires a user to open a crafted file. Verify that all Office and WordPad installations across the estate—especially endpoints that handle untrusted documents—have received the update.

7.8100% KEV ransomware PoC ×6
  • Microsoft Office
  • Microsoft WordPad
masshundreds of millions of Office installations worldwide (exact count unknown)
Full article824 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

A sophisticated and "well-funded" hacking group with a penchant for stealing intellectual property and other trade secrets is wreaking havoc in East Asia.

DarkHotel
(Pexels)

A sophisticated and “well-funded” hacking group with a penchant for stealing intellectual property and other trade secrets is wreaking havoc in East Asia by exploiting a series of old, publicly acknowledged software vulnerabilities, according to research conducted by TrendMicro.

The findings are significant because it exposes an active regional threat that continues to invest in new hacking capabilities — including unique backdoor implants and an exfiltration tools — while apparently running multiple, active economic espionage operations.

Dubbed “BlackTech” by security reachers, the clandestine unit is believed to be associated with three separate campaigns dating back to at least 2010. During that time frame, BlackTech relied on a similar server infrastructure to launch attacks but used various different tools and techniques against organizations, allowing them to move laterally across victim networks and ultimately attempt to exfiltrate sensitives files.

“We are confident attributing these three campaigns to BlackTech given the backend infrastructure used and target overlap,” said Trend Micro Vice President Mark Nunnikhoven. “The backend infrastructure — where the stolen data is sent — is unique to these campaigns and it is extremely rare that unrelated criminals groups share infrastructure for targeted attacks.”

BlackTech has in the past used an exploit for a Adobe Flash vulnerability (CVE-2015-5119) that was leaked during the Hacking Team breach. In addition, the group was seen taking advantage of outdated software flaws, all of which have already been patched, in older versions of Microsoft Windows, including the now infamous CVE-2017-0199.

CVE-0199 has become especially popular in recent months amongst cybercrime groups looking for an opening to plant ransomware on a server or computer.

“The ulterior motive of [BlackTech] is to steal important documents from their victims; initial recipients of their attacks are not always their primary target,” Trend Micro’s report reads. “We saw several decoy documents stolen by the attackers that are then used against another target. This indicates that document theft is most likely the first phase of an attack chain against a victim with ties to the intended target.”

Researchers found digital forensic evidence that BlackTech had worked to compromise a variety of companies and organizations, including “privatized agencies and government contractors as well as enterprises in the consumer electronics, computer, healthcare and financial industries,” particularly those based in Taiwan and occasionally in Japan and Hong Kong.

“We’re seeing a continued investment by this group to keep their malware relevant,” said Nunnikhoven. “That’s a strong indicator that this group is having some measure of success.”

He added, “running concurrent targeted campaigns using a variety of techniques takes a lot of effort. That effort would be better spent on other cybercrimes if they weren’t getting what they are after.”

BlackTech is known to send phishing emails that contain malicious Microsoft Word document attachments to the employees of targeted organizations. When opened, the attachment calls out to the attacker’s command and control infrastructure, allowing for the hackers to upload malware.

Experts say that competitive economic espionage, empowered by cyber means, has become common in the East Asia region. Countries like Vietnam are believed to be heavily investing in developing hacking capabilities.

Although the group uncovered by Trend Micro appears to be similar in some respects to another threat actor named “APT12,” revealed by U.S. cybersecurity firm FireEye, Nunnikhoven said there is no definitive proof to confidently link the two entities.

“We currently have no evidence that ties BlackTech to APT12. While there is some similarity in the targets and techniques, there isn’t enough data to draw a link between the two groups,” he said.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/hacking-team-black-tech-trend-micro-ip-theft/