Hackers using Follina Windows zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-30190 | MSDT URL Protocol Remote Code Execution in Microsoft Windows (Follina) CVE-2022-30190 (Follina) is a remote code execution flaw in the Microsoft Windows Support Diagnostic Tool (MSDT) when MSDT is invoked through its ms-msdt URL protocol by a calling application such as Microsoft Word. Attackers trigger it by luring a user into opening a malicious document — typically a Word/RTF file whose link or remotely linked template launches the ms-msdt: URI with attacker-supplied commands — and CVSS 3.1 rates it 7.8 with a local attack vector and required user interaction. A successful exploit runs arbitrary code with the privileges of the calling application, allowing the attacker to install programs, view, change or delete data, or create new accounts in the user's context. Per the CISA data, affected platforms are Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 and 2012 — essentially any Windows installation that ships MSDT, with Office/Word as the common delivery vector. Exploitation is confirmed in the wild: Microsoft acknowledged it as an exploited zero-day, CISA added it to the KEV on 2022-06-14 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.2% (99th percentile), and contemporaneous reporting also tied its use to espionage actors including APT28. Do: Apply Microsoft's security updates per vendor instructions (the fix shipped in the June 2022 Patch Tuesday releases for the affected Windows versions), as required by CISA's KEV. If patching must be delayed, follow Microsoft's documented mitigation to disable the MSDT URL protocol (remove or restrict the HKEY_CLASSES_ROOT\ms-msdt registry key) and enforce Office Protected View / block Word from fetching remote templates over the network. Hunt for exploitation by checking whether Office processes (WINWORD.exe) launch msdt.exe or sdiagnhost.exe, or whether ms-msdt: URIs are invoked unexpectedly. | 7.8 | 99% | KEV ransomware PoC |
| mass≈1 billion+ Windows devices (effectively the entire supported Windows installed base) |
Full article802 words · extracted from therecord.media · click to collapse
Hackers are using a recently disclosed Windows zero-day vulnerability named Follina to spread a widely-used banking trojan with ties to several ransomware groups. The vulnerability — CVE-2022-30190 — is in the Microsoft Support Diagnostic Tool (MSDT) in Windows and is already being exploited by several state-backed threat actors, according to reports from multiple security companies. Follina, which was given its name by cybersecurity expert Kevin Beaumont because the sample references 0438 — the area code of Follina, Italy — currently doesn’t have a patch and allows attackers to “install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights.” Almost immediately after the vulnerability was highlighted, cybersecurity firm Proofpoint said that Chinese state-sponsored hacking groups were seen exploiting the zero-day in attacks on organizations associated with the Tibetan Government in Exile. The campaigns impersonate the “Women Empowerments Desk” of the Central Tibetan Administration, the firm said. On Tuesday, Proofpoint shared evidence that a threat actor they’ve named “TA570” – who they’ve been tracking since 2018 and is heavily associated with the Qbot malware – is now using CVE-2022-30190 to deliver the popular malware used to steal banking information. “Actor uses thread hijacked messages with HTML attachments which, if opened, drop a zip archive,” the company explained on Twitter. “Archive contains an IMG with a Word doc, shortcut file, and DLL. The LNK will execute the DLL to start Qbot. The doc will load and execute a HTML file containing PowerShell abusing CVE-2022-30190 used to download and execute Qbot.” Archive contains an IMG with a Word doc, shortcut file, and DLL. The LNK will execute the DLL to start Qbot. The doc will load and execute a HTML file containing PowerShell abusing CVE-2022-30190 used to download and execute Qbot. Several other cybersecurity experts corroborated Proofpoint’s findings this week. Nicole Hoffman, senior cyber threat intelligence analyst at Digital Shadows, told The Record that Qbot, also known as QakBot, has been identified in attacks where the Follina vulnerability was exploited. Both Hoffman and Recorded Future ransomware expert Allan Liska noted that Qbot has a long history of coordinating with ransomware groups. “QakBot is associated with several ransomware variants, including Conti and Black Basta, given its ability to establish a persistent foothold in target networks. It is likely only a matter of time before a ransomware group takes advantage of this,” Hoffman said. Andrew Brandt, principal researcher at Sophos, said his team has seen Follina being used to deliver other kinds of payloads, but some of them — notably Cobalt Strike — can be used to deliver other malware, or to give ransomware actors a foothold into the network. "But so far there doesn't seem to be any direct connection between a Follina-type attack and a subsequent ransomware incident," Brandt said. Liska echoed those remarks, adding that while it appears QBot is using Follina, he has not seen any ransomware attacks yet exploiting the bug. “But QBot works with a couple of different ransomware groups, so it is likely just a matter of time,” Liska said. New TTPs from #qakbot #qbot discovered by @k3dg3 In case you haven't seen it yet, here's the top and bottom of the res.123 file downloaded by the .docx file. From the top of the file, it seems like the threat actor is feeling pretty cocky right now. Bottom shows #follina use. pic.twitter.com/dMXOTF1te7 Proofpoint previously said Qbot’s operators had been seen delivering several different kinds of ransomware including ProLock and Egregor. France’s Computer Emergency Response Team (CERT-FR), a division of ANSSI, the country’s national cybersecurity agency, released a lengthy report in November that found the Lockean ransomware affiliate group would deploy the QakBot malware during attacks. Qbot has seen a resurgence in activity since the takedown of Emotet, with multiple companies reporting a surge in activity since January 2021. Group-IB researchers found that Qbot has also been used by Prometheus, a cybercrime service that helps malware gangs distribute malicious payloads. Microsoft previously told The Record that it did not know when a patch will be released for CVE-2022-30190 but pointed to the documents they published about ways the issue can be mitigated. Several security researchers tested the issue and found it affects Office 2013, 2016, 2019, 2021, Office ProPlus and Office 365. Researchers published suggestions for security teams of things they can do to limit exposure, including removing the ms-msdt URI schema registry key.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/hackers-using-follina-windows-zero-day-to-spread-qbot-malware