ZeroHour
Cisco Talospublished ()ingested

Threat Spotlight: Group 72

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2012-1889
Memory Corruption RCE in Microsoft XML Core Services

Microsoft XML Core Services (MSXML) contains a memory corruption flaw (CWE-119) that can allow remote code execution when the component processes attacker-crafted content, such as a malicious web page or XML document loaded through Internet Explorer. Successful exploitation lets an attacker run arbitrary code in the security context of the logged-on user, gaining the ability to install programs, and view, change, or delete data; an admin-context victim would yield full system compromise. Any Windows system shipping the affected MSXML components is affected, which at the time of disclosure meant essentially the entire Windows installed base. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-06-08, EPSS assigns it an 83.6% probability of exploitation in the next 30 days (top percentile), and related reporting ties it to observed in-the-wild and APT activity, though public ransomware association is listed as unknown. No public proof-of-concept is cataloged, but the KEV and EPSS signals indicate active, ongoing exploitation risk.

Do: Apply the vendor updates for XML Core Services released in the July 2012 Patch Tuesday on all Windows systems, prioritizing internet-facing and legacy endpoints, per the CISA KEV required action. Because exploitation is triggered via crafted web/XML content, restrict or upgrade legacy Internet Explorer usage and block untrusted web content on affected hosts. Hunt for exploitation indicators given the 2022-06-08 KEV listing and high EPSS score, and verify MSXML-related patches are present in your patch inventory.

84% KEV
  • Microsoft XML Core Services (MSXML)
mass≈hundreds of millions of Windows endpoints (MSXML ships as a core Windows component)
CVE-2012-4792
Use-After-Free RCE in Microsoft Internet Explorer (CISA KEV)

Microsoft Internet Explorer contains a use-after-free vulnerability (CWE-416) in which an attacker can trigger access to an object that was either never properly allocated or has already been deleted, demonstrated in the flaw record by a CDwnBindInfo object. A remote attacker exploits it by enticing a user to a crafted web site, and successful exploitation yields arbitrary code execution in the context of the logged-on user. Potentially affected parties are users of Microsoft Internet Explorer, which CISA notes is an end-of-life product. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-23, carries a 78.7% EPSS probability of exploitation within 30 days (top percentile), and related reporting ('Miniduke: Web Based Infection Vector', 'Group 72') underscores web-based infection vectors for this class of IE flaw; no public PoC is known and ransomware use is unknown.

Do: Per CISA's required action, the impacted product is end-of-life: retire or disconnect any systems still relying on Internet Explorer and move users to a supported browser such as Microsoft Edge. Audit legacy Windows hosts, kiosks, and line-of-business web apps that still invoke IE, and where a supported platform allows it apply Microsoft's cumulative Internet Explorer security update addressing this CVE (MS13-002). On any remaining legacy systems, restrict web browsing to trusted sites until the software is retired.

79% KEV
  • Microsoft Internet Explorer
masshundreds of millions of users historically (IE shipped as the default Windows browser); current still-vulnerable install base unknown
CVE-2013-3893
Memory Corruption RCE in Microsoft Internet Explorer

CVE-2013-3893 is a resource-management (memory corruption) flaw in Microsoft Internet Explorer that can allow remote code execution (CWE-399). It is triggered remotely, typically when a user views attacker-controlled web content in a vulnerable version of Internet Explorer. A successful attacker gains the ability to execute arbitrary code in the context of the current user, potentially compromising the workstation. Organizations still running Internet Explorer, which CISA notes may be end-of-life (EoL) and/or end-of-service (EoS), are affected; specific affected version ranges were not provided in the source data. The flaw was patched in Microsoft's October 2013 Patch Tuesday after being exploited in the wild (Operation DeputyDog, per related reporting), and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-08-12 with a very high EPSS of 85.9% (100th percentile), indicating active or imminent exploitation.

Do: Apply mitigations per Microsoft's vendor instructions and follow applicable BOD 22-01 guidance for cloud services, or discontinue use of Internet Explorer if mitigations are unavailable, per CISA's required action. Verify that affected systems have the October 2013 Patch Tuesday (or later) cumulative Internet Explorer security updates installed, and audit your estate for remaining legacy IE usage. Where IE is still needed for legacy sites, migrate to Microsoft Edge with IE mode and treat in-the-wild exploitation as likely given the KEV listing and 85.9% EPSS.

86% KEV
  • Microsoft Internet Explorer
masstens to hundreds of millions of legacy Windows devices historically capable of running IE; current actively used legacy IE installs unknown but plausibly in…
CVE-2014-0322
Use-After-Free Remote Code Execution in Microsoft Internet Explorer

CVE-2014-0322 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Internet Explorer that allows remote code execution. It is triggered when the browser processes crafted web content: an attacker-controlled object is freed and then reused, corrupting memory, and in the known campaign FireEye observed it being exploited as a 0-day via a watering hole attack on websites visited by targets. A successful exploit lets an attacker execute arbitrary code with the privileges of the logged-on user, typically through nothing more than a drive-by visit to a compromised web page. Everyone browsing with the affected Internet Explorer versions was exposed, which at the time of disclosure meant on the order of hundreds of millions of desktop users given IE's dominant market share. Exploitation is confirmed in the wild - the flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2022-05-04 - though the source data notes no standalone public proof-of-concept code.

Do: Apply Microsoft's March 2014 Internet Explorer security updates per vendor instructions, as required by the CISA KEV catalog. Inventory endpoints for legacy or unpatched IE usage, restrict browsing with IE on outdated hosts, migrate systems still using IE to a supported browser where possible, and monitor for watering-hole/drive-by compromise indicators.

85% KEV
  • Microsoft Internet Explorer
masshundreds of millions of users at the time of disclosure (IE held the majority of desktop browser share in 2014); residual exposure now limited to legacy…
Full article863 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, October 14, 2014 05:08

This post is co-authored by Joel Esler, Martin Lee and Craig Williams.
Everyone has certain characteristics that can be recognised. This may be a way of walking, an accent, a turn of phrase or a style of dressing. If you know what to look for you can easily spot a friend or acquaintance in a crowd by knowing what characteristics to look for. Exactly the same is true for threat actors.

Each threat actor group may have certain characteristics that they display during their attack campaigns. These may be the types of malware that they use, a pattern in the naming conventions of their command and control servers, their choice of victims etc. Collecting attack data allows an observer to spot the characteristics that define each group and identify specific threat actors from the crowd of malicious activity on the internet.

Talos security and intelligence research group collects attack data from our various telemetry systems to analyse, identify and monitor threat actors through their different tactics, techniques, and procedures. Rather than give names to the different identified groups, we assign numbers to the threat actors. We frequently blog about significant attack campaigns that we discover, behind the scenes we integrate our intelligence data directly into our products. As part of our research we keep track of certain threat actor groups and their activities. In conjunction with a number of other security companies, we are taking action to highlight and disrupt the activities of the threat actors identified by us as Group 72.

Group 72 is a long standing threat actor group involved in Operation SMN, named Axiom by Novetta. The group is sophisticated, well funded, and possesses an established, defined software development methodology. The group targets high profile organizations with high value intellectual property in the manufacturing, industrial, aerospace, defense, media sectors. Geographically, the group almost exclusively targets organizations based in United States, Japan, Taiwan, and Korea. The preferred tactics of the group include watering-hole attacks, spear-phishing, and other web-based tactics.

The tools and infrastructure used by the attackers are common to a number of other threat actor groups which may indicate some degree of overlap. We have seen similar patterns used in domain registration for malicious domains, and the same tactics used in other threat actor groups leading us to believe that this group may be part of a larger organization that comprises many separate teams, or that different groups share tactics, code and personnel from time to time.

It is possible that Group 72 has a vulnerability research team searching for 0-day vulnerabilities in Windows. The group is associated with the initial attack campaigns utilising exploits for the following vulnerabilitiesCVE-2014-0322  and  CVE-2012-4792 . We have also observed them using SQL injection as part of their attacks, and exploits based on  CVE-2012-1889  and CVE-2013-3893.

Frequently the group deploys a remote access trojan (RAT) on compromised machines. These are used both to steal data and credentials from compromised machines, and to use the machine as a staging post to conduct attacks against further systems on the network, allowing the attackers to spread their compromise within the organization. Unlike some threat actors, Group 72 does not prefer to use a single RAT as part of their attacks. We have observed the group to use the following RAT malware:

  • Gh0st RAT (aka Moudoor)
  • Poison Ivy (aka Darkmoon)
  • HydraQ (aka 9002 RAT aka McRAT aka Naid)
  • Hikit (aka Matrix RAT aka Gaolmay)
  • Zxshell (aka Sensode)
  • DeputyDog (aka Fexel) -- Using the kumanichi and moon campaign codes
  • Derusbi
  • PlugX (aka Destroy RAT aka Thoper aka Sogu)
  • HydraQ and Hikit, according to our data are unique to Group 72 and to two other threat actor groups.
    While their operational security is very good, patterns in their domains can be identified such as seemingly naming domains after their intended victim. We have observed domains such as companyname.attackerdomain.com and companyacronym.attackerdomain.com. We have also observed similar patterns in the disposable email addresses used to register their domains. These slips, among others, allow us to follow their activities. Intriguingly we have observed the same email address being used in the activities of this and two other threat actor groups. This may suggest that these three groups are indeed one unit, or possibly hint at shared staff or ancillary facilities.

We will post a follow up with more technical detail in the coming days.

ClamAV names and Snort Signature IDs detecting Group 72 RAT malware:

  • Gh0stRat -- Win.Trojan.Gh0stRAT, 19484, 27964
  • PoisonIVY / DarkMoon -- Win.Trojan.DarkMoon, 7816, 7815, 7814, 7813, 12715, 12724
  • Hydraq -- Win.Trojan.HyDraq, 16368, 21304
  • HiKit -- Win.Trojan.HiKit, 30948
  • Zxshell -- Win.Trojan.Zxshell, 32180, 32181
  • DeputyDog -- Win.Trojan.DeputyDog, 28493, 29459
  • Derusbi -- Win.Trojan.Derusbi, 20080

Protecting Users Against These Threats

Advanced Malware Protection (AMP) is ideally suited to detect the sophisticated malware used by this threat actor.

CWS or WSA web scanning prevents access to malicious websites, including watering hole attacks, and detects malware used in these attacks.

The Network Security protection of IPS and NGFW have up-to-date signatures to detect malicious network activity by threat actors.

ESA can block spear phishing emails sent by threat actors as part of their campaign.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/threat-spotlight-group-72/