New Hacking Campaign Targeting Ukrainian Government with IcedID Malware
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-6882 | Cross-Site Scripting (XSS) in Synacor Zimbra Collaboration Suite Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting flaw (CWE-79) that allows remote attackers to inject arbitrary web script or HTML through the ZCS web interface. An attacker who successfully injects script can execute it in the browser context of a logged-in Zimbra user, enabling actions such as stealing session cookies or credentials, defacing webmail content, or chaining into further compromise; the specific injection vector is not detailed in the available data. Any organization running Zimbra Collaboration Suite, particularly deployments exposing the ZCS webmail interface to the internet, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-19 with known ransomware use, and EPSS estimates a 25.3% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known. Do: Apply the latest Zimbra Collaboration Suite patches per Synacor's vendor instructions, as required by CISA's KEV listing, prioritizing internet-facing webmail servers given confirmed in-the-wild exploitation and known ransomware use. Because the affected version range is not specified in this data, check your current ZCS release against Synacor's advisory and upgrade to any patched release it designates. In the interim, restrict exposure of the ZCS web interface and monitor for unexpected injected script or HTML in webmail content. | 6.1 | 25% | KEV ransomware PoC |
| mass≈ millions of users across tens of thousands of internet-exposed ZCS servers (estimate; public internet-wide scans of Zimbra deployments) |
Full article274 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 18, 2022
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new wave of social engineering campaigns delivering IcedID malware and leveraging Zimbra exploits with the goal of stealing sensitive information.
Attributing the IcedID phishing attacks to a threat cluster named UAC-0041, the agency said the infection sequence begins with an email containing a Microsoft Excel document (Мобілізаційний реєстр.xls or Mobilization Register.xls) that, when opened, prompts the users to enable macros, leading to the deployment of IcedID.
The information-stealing malware, also known as BokBot, has followed a similar trajectory to that of TrickBot, Emotet, and ZLoader, evolving from its earlier roots as a banking trojan to a full-fledged crimeware service that facilities the retrieval of next-stage implants such as ransomware.
The second set of targeted intrusions relate to a new threat group dubbed UAC-0097, with the email including a number of image attachments with a Content-Location header pointing to a remote server hosting a piece of JavaScript code that activates an exploit for a Zimbra cross-site scripting vulnerability (CVE-2018-6882).
In the final step of the attack chain, the injected rogue JavaScript is used to forward victims' emails to an email address under the threat actor's control, indicating a cyber espionage campaign.
The incursions are a continuation of malicious cyber activities targeting Ukraine since the start of the year. Recently, CERT-UA also disclosed that it had foiled a cyberattack by Russian adversaries to sabotage the operations of an unnamed energy provider in the country.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/04/new-hacking-campaign-targeting.html