NSA calls out Russian military hackers targeting mail relay software
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-10149 | Unvalidated Email Recipient Enables Remote Command Execution in Exim MTA CVE-2019-10149 is an improper input validation flaw (CWE-78, OS command injection) in the deliver_message() function in /src/deliver.c of the Exim mail transfer agent, where email recipient addresses are not safely validated before use. A remote attacker triggers it by sending mail whose recipient address contains crafted Exim string-expansion syntax (such as ${run{...}}), causing Exim to expand and execute attacker-supplied operating-system commands during recipient verification or delivery. An attacker gains arbitrary remote command execution on the mail server, commonly with elevated privileges, enabling full system compromise, data theft, ransomware deployment (e.g., the Trinity ransomware campaign), or installation of botnet implants. Any organization running an internet-exposed Exim MTA in the affected version range is at risk, and Exim is widely deployed as the default mail server on many Linux distributions. Exploitation is confirmed in the wild: mass scanning and compromise campaigns began shortly after the June 2019 disclosure, CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-01-10, and its EPSS score of 100% (100th percentile) reflects near-certain near-term exploitation risk. Do: Upgrade Exim to 4.92 or later, or install your distribution's patched Exim package, as required by CISA's KEV action ('apply updates per vendor instructions'); if patching must be delayed, restrict internet-facing SMTP access and tighten recipient-verification configuration. Check mail logs for suspicious MAIL FROM/RCPT TO addresses containing expansion syntax such as ${run{...}} or shell-like commands, and audit patched servers for post-compromise artifacts such as unusual cron jobs, downloaded binaries, or new authorized SSH keys. | 9.8 | 100% | KEV PoC ×5 |
| mass≈500,000+ internet-exposed Exim SMTP servers, with hundreds of thousands likely running vulnerable versions |
Full article705 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The National Security Agency has issued a rare warning publicly attributing exploitation activity to Russian government hackers working for the GRU.
Hackers working for Russia’s military intelligence agency have been exploiting a vulnerability in a mail relay software since August of last year, according to an alert issued Thursday by the National Security Agency.
The NSA publicly attributes the actions to the Russian military’s Main Center for Special Technologies (GTsST). That group is more commonly known as Sandworm, the hacking group believed to be responsible for Ukraine grid disruptions.
The alert comes amid a broader agency effort to publicly share more unclassified threat intelligence. The NSA established a cybersecurity directorate last year to take the reins on providing real-time information in the hopes to prevent digital intrusions against U.S. networks.
The Exim Mail Transfer Agent (MTA) vulnerability exploited in this case, CVE-2019-10149, allows the threat actors to execute commands and code remotely.
When Sandworm exploits the vulnerability, victim machines download and execute a shell script from a Sandworm-controlled domain, according to the NSA. The script then works to disable network security settings, add privileged users, and execute an additional script to allow further exploitation.
When the patch for the vulnerability was issued last year, there was “no evidence” anyone was actively exploiting it, according to Exim. Within weeks of the patch being issued, the Russian military hackers began their onslaught.
The NSA is urging users to patch the flaw immediately in light of Sandworm’s exploitation. The vulnerability, if left unpatched, is “any attacker’s dream access,” the NSA said.
The NSA also issued guidance on how to detect attempts at exploiting the vulnerability, including advice on querying traffic logs and reviewing network security devices. The NSA also shared indicators of compromise, such as IP addresses and domains, associated with the attacks.
“Using a previous version of Exim leaves a system vulnerable to exploitation,” the NSA guidance says. “System administrators should continually check software versions and update as new versions become available.”
Since the new directorate launched, the NSA has issued multiple advisories on threats, including ones in enterprise software made by Citrix and Microsoft. Those prior warnings have not explicitly attributed the related malicious activity to foreign government actors.
In one case, the NSA warned about Turla, a Russian threat group, but only went so far as to say the group is “widely reported to be associated with Russian actors.”
The rare attribution from the NSA comes just three months after the U.S. government publicly connected Sandworm with the Russia’s GRU. The U.S. government has previously attributed the NotPetya worm and Olympic Destroyer attacks to the group.
An NSA official told CyberScoop that the agency took the rare step of publicly attributing this activity to the Russian government to prompt administrators to pay attention.
“We hope that by highlighting the risk of exploitation by a significant nation-state malicious actor will spur any vulnerable system owner to patch this known vulnerability,” the NSA official said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nsa-advisory-sandworm-mail-relay-software/