“NetTraveler is Running!” – Red Star APT Attacks Compromise High
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2010-3333 | Stack Buffer Overflow in Microsoft Office RTF Parsing Allows Remote Code Execution CVE-2010-3333 is a stack-based buffer overflow in the way Microsoft Office parses RTF (Rich Text Format) data. An attacker triggers it by convincing a user to open a specially crafted RTF file, including an RTF email that is handed to Office for rendering, with no authentication required beyond the user's action. Successful exploitation allows remote code execution in the context of the logged-on user, giving the attacker a foothold on the workstation. Any Microsoft Office installation within the affected range identified in the December 2012 Microsoft security bulletin is exposed; the source data does not enumerate specific version numbers. The flaw is actively exploited: it is on the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03, ransomware association unknown) and was used in targeted espionage, notably Kaspersky's 'Red October' campaign, with EPSS estimating an 89.5% probability of exploitation within 30 days (100th percentile). Do: Apply the Microsoft updates from the December 2012 security bulletin that fixes this RTF parsing flaw across all Office/Word installations, prioritized given the ~90% EPSS score and CISA KEV listing. As interim mitigation, block or inspect inbound RTF attachments at email gateways and configure Outlook to read email in plain text so RTF content does not open automatically in Office. Inventory legacy or unpatched Office installations that may have missed the 2012 update, since these remain the likely current exposure. | — | 89% | KEV |
| masshundreds of millions of Office users/installations at time of disclosure (current unpatched legacy installs unknown) | |
| CVE-2012-0158 | Remote Code Execution in Microsoft MSCOMCTL.OCX (Windows Common Controls) CVE-2012-0158 is a remote code execution flaw in Microsoft's MSCOMCTL.OCX, the Windows Common Controls ActiveX component, where improper handling of crafted input allows memory corruption and code execution. It is typically triggered when an application that uses the control (most commonly Microsoft Office) processes specially crafted content, such as a malicious document or file, meaning a victim usually has to open attacker-supplied content. Successful exploitation lets an attacker run arbitrary code and take complete control of the affected system with the privileges of the current user. Any Windows system carrying a vulnerable copy of MSCOMCTL.OCX — including systems where the control was redistributed by legacy applications — is affected, which makes the potential population very large. Exploitation is confirmed and ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and EPSS assigns it the maximum reported probability of exploitation within 30 days. Do: Apply the Microsoft security update for MSCOMCTL.OCX (per vendor instructions, per CISA's required action) on all systems, prioritizing endpoints and servers that open Office documents. Because exploitation commonly arrives via malicious documents, treat unsolicited Office/RTF attachments with suspicion and verify that applications that redistribute MSCOMCTL.OCX have installed a patched copy. Scan the estate for the presence and version of MSCOMCTL.OCX, especially on legacy Windows/Office installations that may be missed by routine patching. | — | 100% | KEV ransomware |
| masshundreds of millions of Windows systems potentially affected |
Full article525 words · extracted from securelist.com · click to collapse
Over the last few years, we have been monitoring a cyber-espionage campaign that has successfully compromised more than 350 high profile victims in 40 countries. The main tool used by the threat actors during these attacks is NetTraveler, a malicious program used for covert computer surveillance.
The name NetTraveler comes from an internal string which is present in early versions of the malware: NetTraveler Is Running! This malware is used by APT actors for basic surveillance of their victims. Earliest known samples have a timestamp of 2005, although references exist indicating activity as early as 2004. The largest number of samples we observed were created between 2010 and 2013.

The NetTraveler builder icon
Known targets of NetTraveler (also known as Travnet or Netfile) include Tibetan/Uyghur activists, oil industry companies, scientific research centers and institutes, universities, private companies, governments and governmental institutions, embassies and military contractors:

The NetTraveler victims map
The following map lists the victim profiles by industry:

Note: this chart does not include the victims that couldnt be identified.
Key findings on the NetTraveler attacks:
- The highest number of infections was located in Mongolia, followed by India and Russia. In total, infections were identified in 40 countries including Kazakhstan, Kyrgyzstan, China, Tajikistan, South Korea, Spain, Germany, the United States, Canada, the United Kingdom, Chile, Morocco, Greece, Belgium, Austria, Ukraine, Lithuania, Belarus, Australia, Hong Kong, Japan, China, Iran, Turkey, Pakistan, Thailand, Qatar, and Jordan.
- The group has infected victims across multiple industries including government institutions, embassies, oil and gas industry, research institutes, military contractors and activists.
- Most recently, the NetTraveler groups main domains of interest for cyber-espionage activities include space exploration, nanotechnology, energy production, nuclear power, lasers, medicine and communications.
- During our research, we identified six victims that had been infected by both NetTraveler and Red October.
- Kaspersky Labs products detect and neutralize the malicious programs and its variants used by the NetTraveler Toolkit, including Trojan-Spy.Win32.TravNet and Downloader.Win32.NetTraveler. Kaspersky Labs products detect the three Microsoft Office exploits used in the spear-phishing attacks, including Exploit.MSWord.CVE-2010-3333, Exploit.Win32.CVE-2012-0158.
Based on collected intelligence, we estimate the group size to about 50 individuals, most of which speak Chinese natively and have working knowledge of the English language NetTraveler is designed to steal sensitive data as well as log keystrokes, and retrieve file system listings and various Office or PDF documents.
The NetTraveler Attacks – Part 1 (public):
- Executive summary
- Attack analysis
- C&C infrastructure
- Statistics
- Mitigation
- Conclusions
For more information, read our full paper TheNetTravelerAttacks, Part 1 [PDF]
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/nettraveler-is-running-red-star-apt-attacks-compromise-high-profile-victims/35936/