Austrian Investigation Reveals Spyware Targeting Law Firms, Finance Institutions
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22047 | Local Privilege Escalation in Windows CSRSS Affects Nearly All Windows Versions CVE-2022-22047 is an elevation-of-privilege vulnerability in the Windows Client Server Run-time Subsystem (CSRSS), a core user-mode process that handles console and system tasks, caused by an untrusted search path (CWE-426). An attacker who already has a low-privileged foothold on a Windows machine can trigger the flaw locally, with no user interaction, to elevate to SYSTEM/administrator-level privileges. Because CSRSS is present on essentially every Windows installation, the affected population spans Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012, meaning virtually every Windows desktop, laptop, and server in active use is potentially affected. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on July 12, 2022 with an August 2 patch deadline for federal agencies, and EPSS assigns it an 18.8% probability of exploitation within 30 days (97th percentile). Do: Apply Microsoft's July 12, 2022 (Patch Tuesday) security updates immediately across all affected releases, including Windows 7, 8.1, RT 8.1, and Server 2008/2012, where fixes arrive through the same July update servicing; CISA's KEV deadline for federal agencies is August 2, 2022. Treat any host where a local attacker has executed code as potentially compromised to SYSTEM level, and hunt for post-exploitation activity. Keep monitoring vendor guidance, as recent reporting suggests some patched Windows attack surfaces may still be exploitable, so continue applying follow-on Windows updates as they ship. | 7.8 | 19% | KEV |
| mass≈1 billion+ Windows devices and servers (the affected list spans Windows 7 through Windows 11 and legacy server releases) |
Full article353 words · extracted from infosecurity-magazine.com · click to collapse
The Austrian government said on Friday it was investigating a company based within the nation’s territory for allegedly developing spyware targeting law firms, banks, and consultancies across at least three countries.
The news comes days after Microsoft’s Threat Intelligence Center (MSTIC) said it found malware called Subzero (CVE-2022-22047) deployed in 2021 and 2022.
According to the tech giant, Subzero was developed by Vienna-based company DSIRF (tracked by Microsoft under the codename KNOTWEED), and deployed through a variety of methods, including 0-day exploits in Windows and Adobe Reader.
For context, DSIRF operates under the guise of helping multinational corporations conduct risk analysis and collect business intelligence.
However, Microsoft’s advisory has linked the company to the sale of spyware used for unauthorized surveillance.
“Observed victims to date include law firms, banks, and strategic consultancies in countries such as Austria, the United Kingdom, and Panama,” MSTIC wrote.
“It’s important to note that the identification of targets in a country doesn’t necessarily mean that a DSIRF customer resides in the same country, as international targeting is common.”
Microsoft said it found multiple links between DSIRF and the exploits and malware used in these attacks.
“These include command-and-control infrastructure used by the malware directly linking to DSIRF, a DSIRF-associated GitHub account being used in one attack, a code signing certificate issued to DSIRF being used to sign an exploit, and other open-source news reports attributing Subzero to DSIRF.”
Additionally, the security researchers explained that, while exploiting CVE-2022-22047 requires attackers to be able to write a DLL to disk, in the threat model of sandboxes (like Adobe Reader and Chromium), the ability to write out files where the attacker cannot control the path isn’t considered dangerous.
“Hence, these sandboxes aren’t a barrier to the exploitation of CVE-2022-22047.”
Microsoft confirmed that the exploit used by DSIRF has now been patched in a security update.
“Microsoft Defender Antivirus detects the malware tools and implants used by KNOTWEED starting with signature build 1.371.503.0.”
Despite the advisory, Austria's interior ministry said it had not recently received reports of any incidents. DSIRF also refuted the claims in an article by Austria's Kurier newspaper.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/austria-spyware-law-firms-finance/