ZeroHour
Security Affairspublished ()ingested @securityaffairs

Buckeye group used Equation Group tools prior to ShadowBrokers leak

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-0143
Remote Code Execution in Microsoft Windows SMBv1 (EternalBlue family)

CVE-2017-0143 is a remote code execution flaw in the SMBv1 server implementation shipped with a wide range of Windows releases; it is one of the March 2017 'MS17-010' SMBv1 bugs (an EternalBlue-family flaw) and is distinct from CVE-2017-0144, -0145, -0146 and -0148. An attacker triggers it by sending specially crafted packets to a target's SMBv1 service over the network, gaining the ability to execute arbitrary code on the host. Because SMB is commonly reachable inside enterprise networks (and sometimes from the internet), exploitation has enabled wormable spread, ransomware (WannaCry), coin miners (Adylkuzz), and DOUBLEPULSAR backdoor implants. Anyone running unpatched, SMBv1-enabled systems from the affected list is exposed: Windows from Vista/Server 2008 through Windows 10 1607 and Server 2016, plus third-party products embedding Windows, including Philips IntelliSpace Portal and Siemens ACUSON/syngo/Versant medical systems. Exploitation is heavily confirmed in the wild: the Buckeye group used the tools before the Shadow Brokers leak, followed by mass exploitation by WannaCry, Adylkuzz, Uiwix and EternalRocks; the flaw is in CISA's KEV (added 2021-11-03, ransomware use known) and EPSS is 93.3%.

Do: Apply Microsoft's MS17-010 security updates (March 2017 cumulative updates or later) to all listed Windows versions, per the CISA KEV required action. Disable SMBv1 where feasible, block or restrict inbound TCP 445 from untrusted networks, and check exposed hosts for DOUBLEPULSAR implants; public Metasploit modules (EternalBlue/EternalRomance/EternalSynergy/EternalChampion) can be used to verify exploitability. For Philips IntelliSpace Portal and Siemens ACUSON/syngo/Versant medical systems, apply the vendors' MS17-010 firmware/advisory updates.

8.893% KEV ransomware PoC ×5
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2
  • Microsoft Windows Server 2008 R2 SP1
  • +9 more
masshundreds of millions of Windows installations potentially affected (SMBv1 enabled by default), with hundreds of thousands of hosts exposing SMB/port 445…
CVE-2019-0703
Windows SMB Server Information Disclosure Vulnerability (CVE-2019-0703)

CVE-2019-0703 is an information disclosure flaw in the way the Windows SMB Server handles certain requests, meaning the server can leak memory contents beyond what it should return in response to crafted SMB requests. Per its CVSS vector (AV:N/AC:L/PR:L), an attacker who can reach the SMB service and holds a low-privileged (valid) account can trigger the condition with no user interaction and no integrity or availability impact, but with high confidentiality impact. Affected systems are unpatched Windows 7, 8.1, RT 8.1, Windows 10 builds 1507 through 1809, Windows Server 2008, and Windows Server versions 1709 and 1803, on which the SMB Server is commonly enabled by default. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2022-05-23, confirming exploitation in the wild, although no public proof-of-concept is known and any ransomware association is unknown. The required action per CISA is to apply the vendor's updates.

Do: Apply Microsoft's security updates for all affected Windows client and server versions, per the CISA KEV required action; for aged installs such as Windows 7 and Server 2008, confirm the patch is present or that extended-security-update coverage applies. Until patched, restrict SMB (TCP/445) exposure to trusted networks only and limit the availability of valid low-privileged credentials, since exploitation per the CVSS vector requires authentication. Prioritize systems that expose SMB externally and maintain an inventory of remaining unpatched hosts.

6.510% KEV
  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809
  • Microsoft Windows 7 as listed in CPE data (all supported editions at time of disclosure)
  • Microsoft Windows 8.1 as listed in CPE data (all supported editions at time of disclosure)
  • +3 more
masshundreds of millions of Windows client and server installations (SMB Server is enabled by default on essentially all Windows systems)
Full article850 words · extracted from securityaffairs.com · click to collapse

China-linked APT group tracked as APT3 was using a tool attributed to the NSA-linked Equation Group more than one year prior to Shadow Brokers leak.

China-linked APT group tracked as APT3 (aka Buckeye, APT3, UPS Team, Gothic Panda, and TG-0110) was using a tool attributed to the NSA-linked Equation Group more than one year prior to Shadow Brokers leak,

In May 2017, researchers at threat intelligence firm Record Future discovered a clear link between APT3 cyber threat group and China’s Ministry of State Security.

The APT3 cyberespionage group had been active since at least 2009 and its last operation was uncovered in mid-2017.

In 2010, security vendor FireEye identified the Pirpi Remote Access Trojan (RAT) which exploited a then 0-day vulnerability in Internet Explorer versions 6, 7 and 8. FireEye named the threat group APT3 and described them as “one of the most sophisticated threat groups” being tracked at the time.

Since then, APT3 has been actively penetrating corporations and governments in the US, UK and most recently Hong Kong.

In November 2017, US authorities charged three China-based hackers for stealing sensitive information from US-based companies, including Siemens AG, and accessing a high-profile email account at Moody’s.

The three Chinese citizens, Wu Yingzhuo, Dong Hao and Xia Lei, work for the Chinese cybersecurity company Guangzhou Bo Yu Information Technology Company Limited, also known as “Boyusec.”

Buckeye’s arsenal included several pieces of malware, one of which is the popular DoublePulsar NSA-linked implant and an exploit tool dubbed Bemstour.

The DoublePulsar exploit was released publicly in April 2017 by ShadowBrockers hackers that allegedly stole them from the NSA.

The hackers leaked a huge trove of hacking tools and exploit codes used by the US intelligence agency, most of Windows exploits were addressed by Microsoft the month before.

DoublePulsar is sophisticated SMB backdoor that could allow attackers to control the infected systems since its leak it was working on almost any Windows system except on devices running a Windows Embedded operating system.

In August 2016, the Shadow Brokers group announced it had hacked the NSA-linked Equation Group, and in the next months, it leaked many tools after attempting to sell them in various ways.

Now Symantec revealed that its experts found evidence that Buckeye group used a variant of DoublePulsar as early as March 2016 in a targeted attack.

The version of DoublePulsar used by Buckeye is newer than the one in the Shadow Brokers dump.

Since March 2016, Buckeye began delivering an early variant of the DoublePulsar implant using the Trojan.Bemstour tool.

“Beginning in March 2016, Buckeye began using a variant of DoublePulsar (Backdoor.Doublepulsar), a backdoor that was subsequently released by the Shadow Brokers in 2017. DoublePulsar was delivered to victims using a custom exploit tool (Trojan.Bemstour) that was specifically designed to install DoublePulsar.” reads the analysis published by Symantec.

“Bemstour exploits two Windows vulnerabilities in order to achieve remote kernel code execution on targeted computers. One vulnerability is a Windows zero-day vulnerability (CVE-2019-0703) discovered by Symantec. The second Windows vulnerability (CVE-2017-0143) was patched in March 2017 after it was discovered to have been used by two exploit tools—EternalRomance and EternalSynergy—that were also released as part of the Shadow Brokers leak.”

The Bemstour tool exploits two Windows vulnerabilities to get remote kernel code execution on the victim’s machine. The first flaw, tracked as CVE-2019-0703, is a Windows zero-day issue discovered by Symantec. The second flaw, tracked as CVE-2017-0143, is a Windows vulnerability addressed by the tech giant in March 2017 after it was found exploited by the NSA linked exploits EternalRomance and EternalSynergy.

How Buckeye obtained Equation Group tools at least a year prior to the Shadow Brokers leak?

“Based on the timing of the attacks and the features of the tools and how they are constructed, one possibility is that Buckeye may have engineered its own version of the tools from artefacts found in captured network traffic, possibly from observing an Equation Group attack.” concludes Symantec. “Other less supported scenarios, given the technical evidence available, include Buckeye obtaining the tools by gaining access to an unsecured or poorly secured Equation Group server, or that a rogue Equation group member or associate leaked the tools to Buckeye,”

The mystery around Buckeye is not ended here, despite the APT group apparently ceased its operations since mid-2017, its DoublePulsar variant was spotted on September 2018. It seems that the threat actor continues to, to improve the Bemstour tool, Symantec experts found a new sample dated March 23, 2019.

“Mystery also surrounds the continued use of the exploit tool and DoublePulsar after Buckeye’s apparent disappearance.” continues the analysis. “It may suggest that Buckeye retooled following its exposure in 2017, abandoning all tools publicly associated with the group. However, aside from the continued use of the tools, Symantec has found no other evidence suggesting Buckeye has retooled. Another possibility is that Buckeye passed on some of its tools to an associated group,”

Buckeye Timeline_970x1164
[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Buckeye, China)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/85075/malware/buckeye-doublepulsar.html