Chinese Hackers Used NSA Hacking Tools Before Shadow Brokers Leaked Them
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0143 | Remote Code Execution in Microsoft Windows SMBv1 (EternalBlue family) CVE-2017-0143 is a remote code execution flaw in the SMBv1 server implementation shipped with a wide range of Windows releases; it is one of the March 2017 'MS17-010' SMBv1 bugs (an EternalBlue-family flaw) and is distinct from CVE-2017-0144, -0145, -0146 and -0148. An attacker triggers it by sending specially crafted packets to a target's SMBv1 service over the network, gaining the ability to execute arbitrary code on the host. Because SMB is commonly reachable inside enterprise networks (and sometimes from the internet), exploitation has enabled wormable spread, ransomware (WannaCry), coin miners (Adylkuzz), and DOUBLEPULSAR backdoor implants. Anyone running unpatched, SMBv1-enabled systems from the affected list is exposed: Windows from Vista/Server 2008 through Windows 10 1607 and Server 2016, plus third-party products embedding Windows, including Philips IntelliSpace Portal and Siemens ACUSON/syngo/Versant medical systems. Exploitation is heavily confirmed in the wild: the Buckeye group used the tools before the Shadow Brokers leak, followed by mass exploitation by WannaCry, Adylkuzz, Uiwix and EternalRocks; the flaw is in CISA's KEV (added 2021-11-03, ransomware use known) and EPSS is 93.3%. Do: Apply Microsoft's MS17-010 security updates (March 2017 cumulative updates or later) to all listed Windows versions, per the CISA KEV required action. Disable SMBv1 where feasible, block or restrict inbound TCP 445 from untrusted networks, and check exposed hosts for DOUBLEPULSAR implants; public Metasploit modules (EternalBlue/EternalRomance/EternalSynergy/EternalChampion) can be used to verify exploitability. For Philips IntelliSpace Portal and Siemens ACUSON/syngo/Versant medical systems, apply the vendors' MS17-010 firmware/advisory updates. | 8.8 | 93% | KEV ransomware PoC ×5 |
| masshundreds of millions of Windows installations potentially affected (SMBv1 enabled by default), with hundreds of thousands of hosts exposing SMB/port 445… | |
| CVE-2019-0703 | Windows SMB Server Information Disclosure Vulnerability (CVE-2019-0703) CVE-2019-0703 is an information disclosure flaw in the way the Windows SMB Server handles certain requests, meaning the server can leak memory contents beyond what it should return in response to crafted SMB requests. Per its CVSS vector (AV:N/AC:L/PR:L), an attacker who can reach the SMB service and holds a low-privileged (valid) account can trigger the condition with no user interaction and no integrity or availability impact, but with high confidentiality impact. Affected systems are unpatched Windows 7, 8.1, RT 8.1, Windows 10 builds 1507 through 1809, Windows Server 2008, and Windows Server versions 1709 and 1803, on which the SMB Server is commonly enabled by default. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2022-05-23, confirming exploitation in the wild, although no public proof-of-concept is known and any ransomware association is unknown. The required action per CISA is to apply the vendor's updates. Do: Apply Microsoft's security updates for all affected Windows client and server versions, per the CISA KEV required action; for aged installs such as Windows 7 and Server 2008, confirm the patch is present or that extended-security-update coverage applies. Until patched, restrict SMB (TCP/445) exposure to trusted networks only and limit the availability of valid low-privileged credentials, since exploitation per the CVSS vector requires authentication. Prioritize systems that expose SMB externally and maintain an inventory of remaining unpatched hosts. | 6.5 | 10% | KEV |
| masshundreds of millions of Windows client and server installations (SMB Server is enabled by default on essentially all Windows systems) |
Full article618 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalMay 07, 2019
In a shocking revelation, it turns out that a hacking group believed to be sponsored by Chinese intelligence had been using some of the zero-day exploits linked to the NSA's Equation Group almost a year before the mysterious Shadow Brokers group leaked them.
According to a new report published by cybersecurity firm Symantec, a Chinese-linked group, which it calls Buckeye, was using the NSA-linked hacking tools as far back as March 2016, while the Shadow Brokers dumped some of the tools on the Internet in April 2017.
Active since at least 2009, Buckeye—also known as APT3, Gothic Panda, UPS Team, and TG-0110—is responsible for a large number of espionage attacks, mainly against defence and critical organizations in the United States.
Although Symantec did not explicitly name China in its report, researchers with a high degree of confidence have previously attributed [1,2] Buckeye hacking group to an information security company, called Boyusec, who is working on behalf of the Chinese Ministry of State Security.
Symantec's latest discovery provides the first evidence that Chinese state-sponsored hackers managed to acquire some of the hacking tools, including EternalRomance, EternalSynergy, and DoublePulsar, a year before being dumped by the Shadow Brokers, a mysterious group that's still unidentified.
According to the researchers, the Buckeye group used its custom exploit tool, dubbed Bemstour, to deliver a variant of DoublePulsar backdoor implant to stealthily collect information and run malicious code on the targeted computers.
Benstour tool was designed to exploit two then-zero-day vulnerabilities (CVE-2019-0703 and CVE-2017-0143) in Windows to achieve remote kernel code execution on targeted computers.
Microsoft addressed the CVE-2017-0143 vulnerability in March 2017 after it was found to have been used by two NSA exploits (EternalRomance and EternalSynergy) that were leaked by the Shadow Brokers group.
The previously unknown Windows SMB Server flaw (CVE-2019-0703) was discovered and reported by Symantec to Microsoft in September 2018 and patched by the tech giant just last month.
Researchers detected BuckEye's hackers using the combination of the SMB exploit and the DoublePulsar backdoor to target telecommunications companies, as well as scientific research and education institutions in Hong Kong, Luxembourg, Belgium, the Philippines, and Vietnam from March 2016 to August 2017.
How Chinese Hackers Grabbed NSA Hacking Tools?
While Symantec doesn't know how the Chinese hackers got the Equation Group tools before the Shadow Brokers leak, the security firm does state there's a possibility that Buckeye may have captured the code from an NSA attack on their own computers and then reverse-engineered the malware to develop its own version of the tools.
"Other less supported scenarios, given the technical evidence available, include Buckeye obtaining the tools by gaining access to an unsecured or poorly secured Equation Group server, or that a rogue Equation group member or associate leaked the tools to Buckeye," Symantec says.
Buckeye appeared to cease its operations in mid-2017, and three alleged members of the group were indicted in the United States in November 2017. However, even after that, Bemstour and DoublePulsar tools used by Buckeye continued to be used until late 2018 in conjunction with different malware.
Although it is unknown who continued to use the tools, the researchers believe that the Buckeye group may have passed some of its tools to another group or "continued operating longer than supposed."
After the Shadow Brokers leak, the NSA-linked exploit tools were then used by North Korean hackers and Russian intelligence, although the Symantec report suggests no apparent connection between the Buckeye acquisition of tools and the Shadow Brokers leak.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/05/buckeye-nsa-hacking-tools.html