ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Cybercriminals exploit fear and urgency to trick consumers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-3723
Actively Exploited V8 Type Confusion in Google Chrome (CVE-2022-3723)

CVE-2022-3723 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chrome, rated High severity with a CVSS 3.1 score of 8.8. It is triggered remotely when a user renders a crafted HTML page, allowing a remote attacker to potentially exploit heap corruption in the browser; the high confidentiality, integrity, and availability impact reflects likely code execution. All Google Chrome releases prior to 107.0.5304.87 are affected, and per CISA the underlying flaw resides in Google Chromium V8, so Chromium-based browsers embedding the same engine are similarly exposed pending their own updates. The flaw was exploited as a zero-day: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-28, and news coverage describes it as Google's ninth actively exploited Chrome zero-day of 2022, amid reports of spyware vendors exploiting zero-days in the wild. EPSS assigns a 7.9% probability (94th percentile) of exploitation activity in the next 30 days.

Do: Update Google Chrome to 107.0.5304.87 or later on all endpoints and restart the browser to complete the patch, verifying the installed version via chrome://version; apply the corresponding V8/Chromium update in any Chromium-based browsers your organization ships. CISA's KEV required action is to apply updates per vendor instructions, so prioritize managed fleets, user workstations, and any browsers exposed to untrusted web content. No public PoC or workaround is known, so patching is the sole effective mitigation.

8.88% KEV
  • Google Chrome all versions prior to 107.0.5304.87 (flaw is in the V8 engine, identified by CISA as Google Chromium V8)
mass≈3 billion users (Chrome's global install base across desktop and mobile)
CVE-2023-21674
Use-After-Free Privilege Escalation in Microsoft Windows ALPC

CVE-2023-21674 is a use-after-free flaw (CWE-416) in the Windows Advanced Local Procedure Call (ALPC) facility, the kernel-level mechanism Windows uses for fast communication between processes and system services. An attacker who can already run code on a Windows machine can trigger the bug by sending crafted ALPC requests, corrupting memory in a privileged process. Successful exploitation allows a local, low-privileged attacker to elevate to SYSTEM/administrator privileges, typically to gain full control of the host or to complete an exploit chain after an initial compromise. Essentially all supported Windows client and server installations from Microsoft are affected; the source data does not list specific versions, and the fix shipped with Microsoft's January 2023 Patch Tuesday, which addressed a record 974 vulnerabilities including this and one other actively exploited Windows zero-day. CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2023-01-10, confirming exploitation in the wild; no public proof-of-concept is known, ransomware use is undetermined, and EPSS estimates a 41.8% probability of exploitation in the next 30 days (99th percentile).

Do: Apply Microsoft's January 2023 (released 2023-01-10) or later Windows cumulative security updates to all Windows clients and servers, per CISA's required action to 'apply updates per vendor instructions.' Because this is a local privilege escalation, prioritize hosts where low-privileged users or untrusted code execute, such as endpoints, RDS/VDI servers, and multi-user systems, and verify installation via your update-management inventory. Treat this as actively exploited; with no public PoC or documented workaround, timely patching is the primary mitigation.

8.842% KEV
  • Microsoft Windows
mass≈1 billion+ Windows installations (Windows active installed base, nearly all unpatched-at-time systems in scope)
Full article982 words · extracted from helpnetsecurity.com · click to collapse

Cybercriminals remained active in spying and information stealing, with lottery-themed adware campaigns used as a tactic to obtain people’s contact details, according to Avast. Threats using social engineering to steal money, such as refund and invoice fraud and tech support scams, increased during Q4 of 2022.

cybercriminals trick consumers

Threat researchers also discovered zero-day exploits in Google Chrome and Windows. These vulnerabilities have since been patched.

“At the end of 2022, we have seen an increase in human-centered threats, such as scams tricking people into thinking their computer is infected, or that they have been charged for goods they didn’t order. It’s human nature to react to urgency, fear and try to regain control of issues, and that’s where cybercriminals succeed,” said Jakub Kroustek, Avast Malware Research Director.

“When people face surprising pop-up messages or emails, we recommend they stay calm and take a moment to think before they act. Threats are so ubiquitous today that it’s hard for consumers to keep up. It is our mission to help protect people by detecting threats and alerting users before they can do any harm, using the latest AI-based technology,” Kroustek continued.

Tech support scams

The Avast threat labs also saw an increase in tech support scam activity. Top affected countries include the United States, Brazil, Japan, Canada, and France.

These scams often start with a pop-up window that alerts people of an alleged malware infection and urges them to call a helpline to resolve the issue.

Scammers will convince the caller to set up a remote connection to their computer, opening the door to theft of personal information and money, as the criminals try to access people’s bank accounts or crypto wallets, and ask for a payment for their services.

“We recommend people ignore such pop-up messages and close the window with the escape key, or if that’s not possible, restart their computer,” advises Kroustek. “Also, never give remote access to your computer to somebody you don’t know.”

Refund and invoice fraud

The Avast threat labs also saw an uptick in refund and invoice fraud of 14% from October to November 2022, and another increase of 22% in December.

Refund fraud works in a comparable way to tech support scams, and often comes in the form of an email that looks like it was sent from a trusted company.

People will receive an email including a fake receipt making them believe they were charged for a purchase they didn’t make. People are then tricked into calling a phone number, where an agent asks them to create a remote connection to their computer and open their banking account, so the person can see how the refund is done.

The goal of the attacker is to steal the person’s money. In the case of invoice fraud, people, and more often businesses, receive bills for goods or services the business never ordered or received.

“To avoid invoice fraud, people need to pay close attention to invoices they receive. Fraudulent invoices often look legitimate, and people need to verify whether an order really was made, the service received, and whether the sender is truly who they pretend to be ,” said Kroustek.

Information stealing adware

Web-based adware was also prevalent in the quarter, not only annoying people with intrusive ads, but also trying to steal their personal data. For example, people are asked to take part in a lottery, spinning a roulette wheel to win, and are then asked to enter their contact information and pay a “handling fee” using their credit card or Google Pay or Apple Pay account.

Avast researchers also saw a flood of DealPly adware, which comes as a Google Chrome extension and sends statistical and search information to the attackers. The risk to get infected by DealPly increased around the world, most significantly in the Americas, in Europe, and South and Southeast Asia.

Avast researchers saw a significant increase of 437% in the global spread of the Arkei information stealer, which is known for stealing data from browsers’ autofill forms, passwords and other sources.

There was also a 57% increase in people and businesses protected against AgentTesla, a strain of malware that often spreads through phishing emails to businesses and designed to steal credentials, as well as a 37% increase in RedLine stealer, which often spreads in cracked games and services, stealing information from browsers and cryptowallets.

Remote access trojans and bots

Avast telemetry also shows that the global spread of LimeRAT tripled in Q4. LimeRAT is a remote access trojan capable of stealing passwords, cryptocurrencies, driving DDoS attacks and installing ransomware on a victim’s computer.

It was mostly active in South and Southeast Asia and Latin America. The Emotet botnet, also a malware distributor with a wide variety of capabilities to steal information and spread malware, has evolved its technique of evading detection by antivirus software in the past few months through the use of timers to incrementally continue the payload’s execution.

The Qakbot information stealer botnet has also evolved further and started using “HTML smuggling” to hide an encoded malicious script within an email attachment. For example, the threat actors have started abusing SVG images to hide malicious payloads and the code used for its reassembly.

Zero-day exploits in the wild

Two zero-day exploits were also discovered by Avast researchers in the quarter.

The first, CVE-2022-3723, was a type confusion in V8 and used to do a ‘get Remote Code Execution’ (RCE) against Google Chrome. Avast reported this vulnerability to Google who quickly rolled out a patch in just two days, on October 27, 2022.

The second zero-day CVE-2023-21674, was an LPE vulnerability in ALPC that allowed attackers to get from the browser sandbox all the way into the Windows kernel. Microsoft patched this exploit in the January 2023 Patch Tuesday update.

The Avast report also shares insights into spyware, and the latest in mobile banking Trojans and Trojan SMS.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/02/13/cybercriminals-exploit-fear-urgency-trick-consumers/