New SnapMC group extorts companies after short 30
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-18935 | Unauthenticated .NET Deserialization RCE in Progress Telerik UI for ASP.NET AJAX CVE-2019-18935 is a .NET deserialization flaw (CWE-502) in the RadAsyncUpload function of Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023. It is triggered when an attacker who knows the Telerik upload encryption keys — most commonly because the earlier flaws CVE-2017-11317 or CVE-2017-11357 exposed them, though keys can be obtained by other means — sends crafted serialized data to RadAsyncUpload, allowing remote code execution without authentication. Successful exploitation gives an attacker arbitrary code execution on the hosting IIS/ASP.NET web server, reflected in the critical 9.8 CVSS score. Any web application built with Telerik UI for ASP.NET AJAX at or below 2019.3.1023 is affected, unless 2019.3.1023 has the non-default hardening setting enabled (as of 2020.1.114 a default setting prevents the exploit). Exploitation is rampant in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, carries a 99.7% EPSS probability of exploitation, has multiple public exploits (Bishop Fox, RAU_crypto, noperator), and has been used by multiple threat groups — including ransomware and government-linked actors — to breach organizations including a U.S. federal agency. Do: Upgrade to Progress Telerik UI for ASP.NET AJAX 2020.1.114 or later, where a default setting prevents exploitation (or, if staying on 2019.3.1023, enable the non-default hardening setting); per CISA KEV, apply updates per vendor instructions. Because exploitation requires the encryption keys to be known, also patch the older CVE-2017-11317/CVE-2017-11357 key-disclosure flaws or rotate the Telerik upload encryption keys. Check internet-facing IIS/ASP.NET applications for exposed RadAsyncUpload handlers and indicators of compromise, given known ransomware and federal-agency breaches. | 9.8 | 100% | KEV ransomware PoC ×4 |
| largeTens of thousands of internet-exposed ASP.NET/IIS web applications using Telerik controls (order-of-magnitude estimate) |
Full article411 words · extracted from therecord.media · click to collapse
Security researchers have discovered a new threat actor that carries out lightning-fast hacks, typically under 30 minutes, steals a company's files, and then extorts the victim with threats to leak the data online or to media outlets unless a ransom payment is made within a few days. Discovered by Dutch security firm Fox-IT, the company named the group SnapMC because of its short-lived intrusions and the use of a tool called mc.exe for data exfiltration. Fox-IT researchers said the group typically breaches company networks via vulnerabilities in web-facing software, with several intrusions linked to the exploitation of CVE-2019-18935, a vulnerability in a UI component for the Telerik ASP.NET framework. Once inside, the group moves fast to collect data from local systems and typically doesn't spend more than 30 minutes on a hacked network. Following a successful exfiltration, SnapMC operators send emails to the hacked company with a list of the stolen files as evidence. Companies are usually given 24 hours to respond to the email and another 72 hours to negotiate a ransom payment. To coerce companies to begin negotiations, SnapMC publishes small portions of the data, threatens to leak the files online, threatens to tell media outlets about the hack, or notify a victim's customers about the breach. Fox-IT said that during the time they tracked the group, they had not observed it deploying ransomware, despite having access to a victim's internal network, with the group focusing solely on data exfiltration and the subsequent extortion. Furthermore, Fox-IT said they also haven't been able to link the SnapMC group to any of the current "leak markets," which are web portals used to leak data from ongoing or failed extortion attempts. Currently active leak and data auction sites include the likes of: Earlier today, Fox-IT released a technical report containing the tools and techniques commonly used by SnapMC in their intrusions — in the hopes that companies deploy proper defenses. One of the simplest solutions to block attacks, recommended in the Fox-IT report, was to deploy a web firewall in front of Telerik-based applications since this has been proven to block SnapMC's initial compromise attempts.
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/new-snapmc-group-extorts-companies-after-short-30-minute-hacks