Iran-linked hackers increasingly spy on governments in Gulf region, researchers say
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-30088 | Microsoft Windows Kernel TOCTOU Race Condition Privilege Escalation (CVE-2024-30088) CVE-2024-30088 is a time-of-check to time-of-use (TOCTOU) race condition in the Microsoft Windows kernel (CWE-367) that allows a local, low-privileged attacker to elevate to SYSTEM-level privileges. Because it is a timing race with high attack complexity, exploitation requires locally executing crafted code that repeatedly races the kernel's validation of a resource, but no user interaction is needed and the attacker only needs the ability to already run code on the target. Successful exploitation grants full control of the local machine (high confidentiality, integrity, and availability impact), which attackers typically chain after initial access or another flaw to gain complete host compromise. Virtually all supported Windows 10 and Windows 11 client releases and Windows Server 2016 through 2022 23H2 are affected if unpatched. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, Iran-linked OilRig used it in an espionage campaign targeting UAE and Gulf governments, and EPSS assigns a ~68% probability of exploitation within 30 days (99th percentile). Do: Apply the Windows cumulative security update for CVE-2024-30088 from Microsoft's advisory on every affected Windows 10, Windows 11, and Windows Server release (the fix shipped in Microsoft's June 2024 monthly security updates; confirm your build number against the advisory). Prioritize multi-user hosts, RDP/jump servers, and endpoints where untrusted users or code run, since this is a local privilege escalation used post-compromise — check endpoint logs for suspicious local process activity coinciding with privilege changes. Consistent with the CISA KEV required action (added 2024-10-15), patch promptly per vendor instructions or discontinue use of affected builds if patching is not possible. | 7.0 | 68% | KEV ransomware |
| mass≈1 billion+ Windows 10/11 client devices and hundreds of thousands to millions of Windows Server hosts (unpatched installed base) |
Full article257 words · extracted from therecord.media · click to collapse
An Iran-linked cyberespionage group has stepped up its attacks in recent months against government agencies in the United Arab Emirates (UAE) and the broader Gulf region, according to a new report. APT34, also known as Earth Simnavaz and OilRig, is believed to be an Iranian state-sponsored threat actor primarily targeting organizations in the Middle East, especially those in the oil and gas industries. The hackers’ recent escalation in activity underscores their “ongoing commitment” to exploiting vulnerabilities within critical infrastructure and government networks in geopolitically sensitive areas, said researchers at the cybersecurity firm Trend Micro in a report released last week. In their latest attacks, APT34 deployed a sophisticated new backdoor named Stealthook to exfiltrate sensitive credentials, including accounts and passwords, through on-premise Microsoft Exchange servers to those controlled by the attackers as email attachments. The group is known for using compromised organizations to conduct supply chain attacks on other government entities, the researchers said. “We expect that the threat actor could use the stolen accounts to initiate new attacks through phishing against additional targets,” they added. The group has also recently exploited the Windows CVE-2024-30088 flaw to escalate their privileges in targeted systems. This demonstrates APT34’s “continuous adaptation” by exploiting newer vulnerabilities to make their attacks stealthier and more effective, Trend Micro said. The researchers warned that government organizations in the Middle East and Gulf region should take the threats from this group “seriously” and improve their defensive measures, because it uses tools to blend malicious activity with normal network traffic and avoid traditional detection methods.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/iran-linked-hackers-espionage-persian-gulf-countries