ZeroHour
Security Affairspublished ()ingested @securityaffairs

Magnet Goblin group used a new Linux variant of NerbianRAT malware

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-24086
Unauthenticated RCE via checkout input-validation flaw in Adobe Commerce/Magento

Adobe Commerce and Magento Open Source versions 2.4.3-p1 and earlier and 2.3.7-p2 and earlier contain an improper input validation flaw (CWE-20) in the checkout process. A remote attacker can trigger it with no privileges and no user interaction by submitting crafted input to a store's checkout flow, and successful exploitation results in arbitrary code execution on the server hosting the storefront. Any Adobe Commerce or Magento Open Source storefront running the affected versions is exposed, and because these are internet-facing e-commerce sites the practical exposure is broad. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15), its EPSS exploitation probability is 99.2% (100th percentile), and news reports describe ongoing attacks against Magento 2 stores, including recurring 'Xurum' attack campaigns and template-based attacks.

Do: Upgrade every store to an Adobe-patched release per the vendor's instructions - i.e., any release newer than 2.4.3-p1 on the 2.4.x line or newer than 2.3.7-p2 on the 2.3.x line - noting that headlines indicate companion Magento CVEs were fixed in the same patch release, so consult Adobe's advisory for the full list. Because exploitation is unauthenticated and confirmed in the wild, prioritize internet-facing shops; WAF rules may reduce risk, but reports indicate WAF bypasses in related Magento attacks, so patching is the only reliable fix. After patching, review web server and application logs for exploitation attempts against the checkout flow and check affected hosts for indicators of compromise.

9.899% KEV
  • Adobe Commerce 2.4.3-p1 and earlier; 2.3.7-p2 and earlier
  • Adobe Magento Open Source 2.4.3-p1 and earlier; 2.3.7-p2 and earlier
massroughly 100,000-300,000 online storefronts (Magento/Adobe Commerce is among the most widely deployed e-commerce platforms)
CVE-2023-41265
+1 in the same advisory: …41266
HTTP Request Tunneling Privilege Escalation in Qlik Sense Enterprise for Windows

CVE-2023-41265 is an HTTP request tunneling flaw (CWE-444) in Qlik Sense Enterprise for Windows that lets a remote attacker tunnel additional HTTP requests inside a single raw HTTP request, causing those requests to be executed by the backend server hosting the repository application. Because the tunneled requests are processed in a trusted backend context, the attacker, who needs only low-privileged access according to the CVSS score, achieves privilege elevation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.9 critical, scope changed). All Windows releases up to and including May 2023 Patch 3, February 2023 Patch 7, November 2022 Patch 10, and August 2022 Patch 12 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-07 with known ransomware use, EPSS places it in the 100th percentile (88.2% probability of exploitation within 30 days), and reporting ties active exploitation to CACTUS ransomware campaigns as well as 1-day attacks delivering NerbianRAT Linux malware. No public proof-of-concept is known, but exploitation is ongoing, making unpatched, especially internet-exposed, Qlik Sense servers a priority for defenders.

Do: Upgrade Qlik Sense Enterprise for Windows to the fixed release for your track: May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13; the August 2023 IR also contains the fix. Per CISA's KEV required action, apply vendor remediations or discontinue use of the product if remediation is unavailable. Given active CACTUS ransomware exploitation of Qlik flaws, prioritize patching internet-exposed servers, restrict access to trusted networks, and check patched and unpatched instances for signs of compromise.

9.9
group max
88% KEV ransomware
  • Qlik Sense Enterprise for Windows May 2023 Patch 3 and earlier (fixed in May 2023 Patch 4)
  • Qlik Sense Enterprise for Windows February 2023 Patch 7 and earlier (fixed in February 2023 Patch 8)
  • Qlik Sense Enterprise for Windows November 2022 Patch 10 and earlier (fixed in November 2022 Patch 11)
  • +1 more
largeroughly 10,000–100,000 installations worldwide, with likely thousands of internet-exposed Qlik Sense servers
CVE-2024-21887
+1 in the same advisory: …46805
Command Injection RCE in Ivanti Connect Secure and Policy Secure

Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available.

Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories.

9.1
group max
100% KEV ransomware PoC
  • Ivanti Connect Secure (ICS, formerly Pulse Connect Secure)
  • Ivanti Policy Secure
largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher)
CVE-2023-48365
HTTP Request Smuggling/Tunneling in Qlik Sense Allows Privilege Escalation

Qlik Sense contains an HTTP tunneling flaw (CWE-444, inconsistent interpretation of HTTP requests, i.e., HTTP request smuggling) in which the application's tunneling component and the backend server hosting the software disagree about HTTP request boundaries. An attacker triggers it by sending crafted HTTP requests through the tunneling mechanism of an affected Qlik Sense deployment. Exploitation lets the attacker escalate privileges and execute HTTP requests against the backend server, reaching internal services and interfaces that should only be accessible to the application. Any organization running an affected Qlik Sense deployment is exposed, with internet-facing instances at greatest risk. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2025-01-13 with ransomware use known, and EPSS assigns a 24.7% probability of exploitation within 30 days (98th percentile); no public PoC is known.

Do: Apply Qlik's remediation for CVE-2023-48365 per the vendor's security instructions, or discontinue use of the product if mitigations are unavailable (CISA KEV required action). Prioritize internet-exposed Qlik Sense servers, and given known ransomware use, hunt for indicators such as unexpected requests arriving at the backend server, anomalous authentication activity, and lateral movement originating from the Qlik host.

9.924% KEV ransomware
  • Qlik Sense
large≈tens of thousands of enterprise deployments, with on the order of a few thousand Qlik Sense servers exposed to the internet
CVE-2024-21888
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privile

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.

NVD description · AI analysis pending
8.887%
  • ivanti connect secure
  • ivanti policy secure
CVE-2024-21893
SSRF in Ivanti Connect Secure, Policy Secure, and Neurons SAML Component

CVE-2024-21893 is a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure (formerly Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons. A remote attacker can trigger the flaw with crafted unauthenticated requests to the SAML component, causing the appliance to make requests to otherwise restricted resources. Successful exploitation allows the attacker to access certain restricted resources without any credentials, and CISA notes the flaw has been used in ransomware operations. Any organization running an affected Ivanti Connect Secure, Policy Secure, or Neurons deployment is exposed, particularly where the appliance is reachable from the internet. The vulnerability is confirmed exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-31, carries an EPSS probability of 100%, and no public proof-of-concept is known.

Do: Apply Ivanti's released patches or the vendor-issued mitigations immediately per vendor instructions, or discontinue use of the product if mitigations are unavailable, as required by CISA. Because ransomware use is documented, review SAML-related logs and appliance audit trails for signs of exploitation and follow-on compromise, and check for indicators of post-exploitation activity. Monitor Ivanti advisories for patched version numbers and updated mitigation guidance, since specific fixed versions are not yet specified in the available data.

8.2100% KEV ransomware
  • Ivanti Connect Secure (formerly Pulse Connect Secure)
  • Ivanti Policy Secure
  • Ivanti Neurons
largetens of thousands of internet-exposed appliances (with total user counts likely in the hundreds of thousands)

Indicators of compromiseAll →

TypeIndicatorContext
ipv4172.86.66.165and the current process ID. Assigns a hardcoded IP address (172.86.66.165) to two global variables, designating them as the primary a
Full article725 words · extracted from securityaffairs.com · click to collapse

The financially motivated hacking group Magnet Goblin uses various 1-day flaws to deploy custom malware on Windows and Linux systems.

A financially motivated threat actor named Magnet Goblin made the headlines for rapidly adopting and exploiting 1-day vulnerabilities, CheckPoint warned. The group focuses on internet-facing services, in at least one instance the group exploited the vulnerability CVE-2024-21887 in Ivanti Connect Secure VPN. The researchers noticed that the exploit became part of the group’s toolkit within just one day after a proof of concept (POC) for it was published.

The researchers observed that the threat actor carried out multiple campaigns targeting Ivanti, Magento, Qlink Sense and possibly Apache ActiveMQ.

The attackers demonstrated the capability to quickly use 1-day vulnerabilities. These include:

In the incident involving the Ivanti Connect Secure VPN exploit, threat actors were spotted dropping a previously undetected Linux variant of a malware dubbed NerbianRAT, along with a JavaScript credential stealer known WARPWIRE.

NerbianRAT for Windows was first spotted in 2022, however the Linux variant employed by Magnet Goblin has been in circulation since May 2022.

Magnet Goblin

“While tracking the recent waves of Ivanti exploitation, we identified a number of activities leading to the download and deployment of an ELF file which turned out to be a Linux version of NerbianRAT. This cluster of activity, also described in a Darktrace report, was characterized by the download of a variety of payloads from an attacker-controlled infrastructure.” reads the report published CheckPoint. “Among the downloaded payloads are a variant of the WARPWIRE JavaScript credential stealer, a NerbianRAT Linux variant, and Ligolo, an open-source tunneling tool written in GO.”

Upon executing the Linux NerbianRAT variant, the malware checks for duplicate processes achieved through the allocation of shared memory segments. If successful, it initiates a self-forking mechanism, constituting the sole anti-debugging/anti-analysis measure incorporated into the malware. Once the check is completed, NerbianRAT starts the main initialization process.

Below are the phases of the initiation process:

  1. Gathers fundamental information, such as the current time, username, and machine name.
  2. Generates a unique bot ID by combining the value of the file /etc/machine-id and the current process ID.
  3. Assigns a hardcoded IP address (172.86.66.165) to two global variables, designating them as the primary and secondary hosts.
  4. Decrypts the global working directory variable and designates it as %TEMP%.
  5. Searches for the file rgs_c.txt, reads its contents, and attempts to interpret them as the following arguments: -pP port -h host.
  6. Loads a public RSA key, subsequently utilized to encrypt network communication

Unlike the Windows variant, the Linux version of NerbianRAT uses raw TCP sockets for communication, exchanging data blobs represented by structs using a customized protocol. The malware uses AES encryption for C2 communication, however, depending on the transmitted data, RSA may also be utilized.

Below are the actions supported by the malware:

Action IDAction description
1Continue requesting more actions.
4Run a Linux command in a separate thread.
5Send the last command result and clean up the result file. ** If a command is running it is stopped.
6Run a Linux command immediately.
7Do nothing / Idle command.
8Change the connection interval global variable.
9Update the start and end worktimes, then save the config file.
14Send back the idle status timings string / the configuration / results of the last run Linux command.
15Set a config variable, based on the name of the field and a value.
16Update the gl_command_buffer global variable, used when executing commands from the C2.

The researchers also observed a simplified version of the NerbianRAT, called MiniNerbian, which supports the following actions:

  • Execute C2’s command and return results
  • Update activity schedule (full day or specific hours)
  • Update configuration

Unlike NerbianRAT, MiniNerbian uses HTTP protocol for C2 communication.

NerbianRAT

“Magnet Goblin, whose campaigns appear to be financially motivated, has been quick to adopt 1-day vulnerabilities to deliver their custom Linux malware, NerbianRAT and MiniNerbian. Those tools have operated under the radar as they mostly reside on edge-devices.” concludes the report. “This is part of an ongoing trend for threat actors to target areas which until now have been left unprotected.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Magnet Goblin)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/160274/cyber-crime/magnet-goblin-nerbianrat-attacks.html