ZeroHour
Security Affairspublished ()ingested @securityaffairs

China-linked APT group MirrorFace targets Japan

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27997
Pre-Auth Heap Buffer Overflow RCE in Fortinet FortiOS/FortiProxy SSL-VPN

CVE-2023-27997 is a heap-based buffer overflow (CWE-122, with associated out-of-bounds write CWE-787) in the SSL-VPN component of Fortinet FortiOS and FortiProxy, reachable by unauthenticated users. A remote attacker can trigger it with specially crafted requests to the SSL-VPN web interface, gaining the ability to execute arbitrary code or commands on the gateway. Full control of an edge VPN/firewall appliance enables credential theft, session hijacking, and pivoting into the protected network, which makes the bug attractive to ransomware operators. Any organization exposing the SSL-VPN portal on the affected FortiOS builds (7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below) or FortiProxy builds (7.2.3 and below, 7.0.9 and below, 2.0.12 and below, and 1.1/1.2 all versions) is potentially exposed. The flaw is under active exploitation: CISA added it to the KEV on 2023-06-13 with known ransomware use, EPSS estimates an ~86% probability of exploitation within 30 days (100th percentile), and reporting indicates it was likely being exploited in the wild, with Fortinet also warning that some attackers retained access to FortiGate devices even after patching.

Do: Apply Fortinet's updates to all SSL-VPN-enabled FortiOS and FortiProxy appliances as required by the CISA KEV listing, upgrading each affected branch beyond the listed versions (end-of-life FortiProxy 1.1/1.2 requires migration to a supported release); if SSL-VPN is not needed, disable the web portal or restrict it to trusted source addresses. After patching, hunt for signs of compromise and rotate credentials and VPN-related secrets, since Fortinet warned that some attackers retained access to FortiGate devices post-patching.

9.886% KEV ransomware
  • Fortinet FortiOS (SSL-VPN) 7.2.4 and below; 7.0.11 and below; 6.4.12 and below; 6.0.16 and below
  • Fortinet FortiProxy (SSL-VPN) 7.2.3 and below; 7.0.9 and below; 2.0.12 and below; 1.2 (all versions); 1.1 (all versions)
masson the order of several hundred thousand internet-exposed SSL-VPN endpoints (≈300k–500k per public scans)
CVE-2023-28461
Unauthenticated RCE in Array Networks AG/vxAG SSL VPN Gateways (ArrayOS)

CVE-2023-28461 is a critical (CVSS 9.8) missing-authentication flaw in Array Networks' AG series and virtual vxAG SSL VPN gateways running ArrayOS 9.4.0.481 and earlier. An unauthenticated remote attacker sends an HTTP request to a vulnerable URL containing a 'flags' attribute in an HTTP header, which allows browsing the filesystem on the SSL VPN gateway; vendor and CERT reporting indicate this can be leveraged into full remote code execution, and JPCERT has confirmed active command-injection attacks. Successful exploitation gives the attacker code execution on the appliance, compromising the VPN gateway and potentially providing a foothold into the protected internal network. Any organization running an affected AG/vxAG gateway is exposed; these are enterprise SSL VPN appliances, with notable deployments in Japan and the wider Asia-Pacific region. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-25 (ransomware use known), JPCERT/CC reports widespread exploitation, Chinese-linked activity including MirrorFace targeting Japanese firms has been reported, and EPSS places the 30-day exploitation probability at 68.1%.

Do: Upgrade AG/vxAG gateways to a fixed ArrayOS release per Array Networks' instructions — as of the 2023-03-09 advisory a fixed release was pending, so apply any release newer than 9.4.0.481 once available; if mitigations are unavailable, discontinue use per the CISA KEV required action, and federal agencies should follow CISA's directive to patch. Review gateway logs and downstream systems for signs of exploitation, and treat any compromised appliance as a potential network foothold given confirmed ransomware use.

9.868% KEV ransomware
  • Array Networks AG series and vxAG SSL VPN gateways (ArrayOS) 9.4.0.481 and earlier
moderatelikely on the order of thousands (roughly 1,000–10,000) of internet-exposed AG/vxAG gateway appliances, each typically serving many remote users (estimate)
CVE-2023-3519
Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway

CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations.

Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise.

9.8100% KEV ransomware PoC
  • Citrix NetScaler ADC Supported releases before the July 2023 fixes, per Citrix advisory: 14.1 before 14.1-8.50; 13.1 before 13.1-49.13; 13.0 before 13.0-82.45; 12.1 before 12.1-55.3
  • Citrix NetScaler Gateway Same affected builds as NetScaler ADC (before 14.1-8.50, 13.1-49.13, 13.0-82.45, 12.1-55.300, and FIPS/NDcPP equivalents); affected when the appliance serves as
largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream…
Full article588 words · extracted from securityaffairs.com · click to collapse

Japanese authorities attributed a cyber-espionage campaign targeting the country to the China-linked APT group MirrorFace.

The National Police Agency (NPA) and the Cabinet Cyber Security Center in Japan have linked a long-running cyber-espionage campaign targeting local entities to the China-linked group MirrorFace (aka Earth Kasha).

The campaign has been active since at least 2019, it targets Japanese technology and national security, evolving methods to steal advanced tech and intelligence.

MirrorFace was first spotted by ESET in 2022, targeting Japanese political entities ahead of elections.

The group exploited vulnerabilities in networking equipment, including CVE-2023-28461 (Array Networks), CVE-2023-27997 (Fortinet), and CVE-2023-3519 (Citrix).

Between 2019 and 2024, the MirrorFace group launched three cyber campaigns targeting Japanese think tanks, government, academia, and key industries.

  • Campaign A (2019–2023): Used emails with malware attachments (LODEINFO) to target politicians, media, and government.
  • Campaign B (2023): Exploited software vulnerabilities in networking devices, focusing on semiconductor, manufacturing, and aerospace sectors.
  • Campaign C (2024): Delivered malware (ANEL) via email links, targeting academia and think tanks, evolving to abuse Visual Studio Code.

These campaigns highlight ongoing efforts to steal advanced technology and national security data.

“Analysis by the NPA Cyber Special Investigation Division, the Metropolitan Police Department, and prefectural police departments indicates that these campaigns are systematic cyberattacks linked to China, primarily aiming to steal information related to Japan’s national security and advanced technologies.” reads the report published by NPA. “This alert serves to publicize the attack methods employed by MirrorFace and raise awareness.”

In both campaigns A and C, attackers used spear-phishing attacks, however, the two campaigns show notable differences in their malware and infection techniques. Campaign A relied on LODEINFO, a type of malware that infected systems primarily through malicious email attachments. In contrast, Campaign C employed ANEL, with infections initiated via links embedded in the email body. Additionally, while earlier campaigns, including Campaign A, were marked by the abuse of Windows Sandbox, Campaign C showcased an evolution in tactics by also exploiting Visual Studio Code (VS Code) to compromise targeted systems.

The China-linked group used two evasion methods in its campaigns, Visual Studio Code (VSCode) tunnels and Windows Sandbox.

MirrorFace has been using Visual Studio Code (VSCode) tunnels since June 2024 to establish covert communication channels on compromised systems. These tunnels receive PowerShell command instructions. This tactic has also been observed with other China-linked APT groups.

Since June 2023, MirrorFace has used the Windows Sandbox feature to execute LOADEINFO malware within an isolated environment, evading antivirus detection. Windows Sandbox allows safe execution of commands, but since the host OS, including Microsoft Defender, does not monitor this virtualized environment, malware can run undetected, communicate with remote servers, and maintain access to the host via shared folders.

The alert issued by Japan NPA recommends System Administrators to:

  • Implement centralized log management to track breaches, as logs are critical for identifying causes and scope. Use tools like SIEM or CISA’s “Logging Made Easy” for log aggregation.
  • Regularly monitor network device logs for abnormal activities, like unauthorized logins or unusual VPN behavior.
  • Ensure that administrative accounts are restricted, and monitor for any inactive accounts.
  • Stay updated on network device vulnerabilities and apply patches promptly.

it also suggests to

  • Disable unnecessary features like Windows Sandbox if not needed and monitor for unauthorized activities like the activation of development tools (e.g., VS Code).
  • Track antivirus detections carefully. Even after malware is removed, continued monitoring is necessary to ensure no undetected threats remain.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, MirrorFace)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172890/apt/china-linked-apt-mirrorface-targets-japan.html