Espionage group uses cybersecurity conference invite as a lure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2012-0158 | Remote Code Execution in Microsoft MSCOMCTL.OCX (Windows Common Controls) CVE-2012-0158 is a remote code execution flaw in Microsoft's MSCOMCTL.OCX, the Windows Common Controls ActiveX component, where improper handling of crafted input allows memory corruption and code execution. It is typically triggered when an application that uses the control (most commonly Microsoft Office) processes specially crafted content, such as a malicious document or file, meaning a victim usually has to open attacker-supplied content. Successful exploitation lets an attacker run arbitrary code and take complete control of the affected system with the privileges of the current user. Any Windows system carrying a vulnerable copy of MSCOMCTL.OCX — including systems where the control was redistributed by legacy applications — is affected, which makes the potential population very large. Exploitation is confirmed and ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and EPSS assigns it the maximum reported probability of exploitation within 30 days. Do: Apply the Microsoft security update for MSCOMCTL.OCX (per vendor instructions, per CISA's required action) on all systems, prioritizing endpoints and servers that open Office documents. Because exploitation commonly arrives via malicious documents, treat unsolicited Office/RTF attachments with suspicion and verify that applications that redistribute MSCOMCTL.OCX have installed a patched copy. Scan the estate for the presence and version of MSCOMCTL.OCX, especially on legacy Windows/Office installations that may be missed by routine patching. | — | 100% | KEV ransomware |
| masshundreds of millions of Windows systems potentially affected |
Full article460 words · extracted from helpnetsecurity.com · click to collapse
A cyber espionage group that has been targeting organizations in Southeast Asia for years is misusing a legitimate conference invite as a phishing lure to trigger the download of backdoor malware.

The APT in question is Lotus Blossom, and the security conference is Palo Alto Networks’ CyberSecurity Summit that is scheduled to take place in Jakarta, Indonesia, on November 3.
About Lotus Blossom
Lotus Blossom is a group that has been operating at least since 2009, and possibly even earlier. Their predilection for spear-phishing emails with an ever-changing array of lures is well-known. They usually deliver custom Trojan backdoors (Elise, Emissary) to the target system.
Over the years, the group has been linked to a variety of targets in Hong Kong, Taiwan, Vietnam, the Philippines, and Indonesia.
The effectiveness of their approach is evident – they wouldn’t continue using spear-phishing emails if they didn’t work.
About the newest campaign
“Palo Alto Networks hosts cyber security summits all over the world, and in many cases we send invitations via email to individuals we believe would be interested in attending,” Palo Alto Networks’ researchers Robert Falcone explained.
It’s possible and likely that the Lotus Blossom team had access to an inbox that received the invite via email, or that they received the email themselves.
They took a screenshot of the image in the legitimate invite’s message body, a screenshot of the summit’s agenda, and combined the two images into a decoy Word document named [FREE INVITATIONS] CyberSecurity Summit.doc.
The researchers weren’t able to get a look at the attack emails, but believe the document is delivered as an attachment. Once opened, it shows the decoy Word document while attempting to exploit an old MS Office vulnerability (CVE-2012-0158) to deliver the backdoor Trojan in the background.
By analyzing the decoy document, the researchers discovered some things about the system on which the attackers created it.
“The threat actor is running Windows localized for Chinese users, which suggests the actor’s primary language is Chinese. The ‘CH’ icon in the Windows tray shows that the built-in Windows input method editor (IME) is currently set to Chinese,” Falcone shared.
“Also, the screenshot shows a popular application in China called Sogou Pinyin, which is an IME that allows a user to type Chinese characters using Pinyin. Pinyin is critical to be able to type Chinese characters using a standard Latin alphabet keyboard, further suggesting the threat actor speaks Chinese.”
At the moment, it’s impossible to known how effective this spear-phishing campaign was, but Palo Alto Networks has temporarily suspended the sending of email invites for the summit.
They also advised recipients of previous and future related emails to scrutinize them to determine if they were sent by the Lotus Blossom threat actors.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2016/10/31/conference-invite-phishing-lure/