The Icefog APT: A Tale of Cloak and Three Daggers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2012-0158 | Remote Code Execution in Microsoft MSCOMCTL.OCX (Windows Common Controls) CVE-2012-0158 is a remote code execution flaw in Microsoft's MSCOMCTL.OCX, the Windows Common Controls ActiveX component, where improper handling of crafted input allows memory corruption and code execution. It is typically triggered when an application that uses the control (most commonly Microsoft Office) processes specially crafted content, such as a malicious document or file, meaning a victim usually has to open attacker-supplied content. Successful exploitation lets an attacker run arbitrary code and take complete control of the affected system with the privileges of the current user. Any Windows system carrying a vulnerable copy of MSCOMCTL.OCX — including systems where the control was redistributed by legacy applications — is affected, which makes the potential population very large. Exploitation is confirmed and ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and EPSS assigns it the maximum reported probability of exploitation within 30 days. Do: Apply the Microsoft security update for MSCOMCTL.OCX (per vendor instructions, per CISA's required action) on all systems, prioritizing endpoints and servers that open Office documents. Because exploitation commonly arrives via malicious documents, treat unsolicited Office/RTF attachments with suspicion and verify that applications that redistribute MSCOMCTL.OCX have installed a patched copy. Scan the estate for the presence and version of MSCOMCTL.OCX, especially on legacy Windows/Office installations that may be missed by routine patching. | — | 100% | KEV ransomware |
| masshundreds of millions of Windows systems potentially affected | |
| CVE-2012-1723 | Remote Arbitrary Code Execution in Oracle Java SE (Hotspot Component) Oracle Java SE's Java Runtime Environment contains an unspecified flaw in its Hotspot component that allows remote attackers to affect confidentiality, integrity, and availability — characterized by CISA as arbitrary code execution. The available data does not document the exact trigger beyond 'unknown vectors related to Hotspot,' but flaws in the JVM's execution engine of this type are typically reached remotely by having the runtime process malicious Java content. A successful attacker gains code execution in the context of the process running the JVM, taking control of the affected host. Any deployment running affected, unpatched Oracle Java SE — particularly legacy JRE installs — is affected. The vulnerability is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) with known ransomware use and a 93.7% EPSS probability of exploitation in the next 30 days, confirming active in-the-wild exploitation, though the reviewed data lists no public PoC. Do: Per CISA's required action, apply updates per vendor instructions: upgrade every Oracle Java SE installation to a currently supported patched release and inventory for legacy JRE builds that predate the 2012 Hotspot fix. Disable or restrict the Java browser plugin where it is not needed, and given known ransomware use, prioritize legacy Java systems for patching and threat-hunting. | — | 94% | KEV ransomware |
| mass≈ millions of endpoints running legacy, unpatched Java (exact count unknown) | |
| CVE-2012-1856 | Remote Code Execution via TabStrip ActiveX Control in Microsoft Office (MSCOMCTL.OCX) CVE-2012-1856 is a remote code execution flaw in the TabStrip ActiveX control in the Common Controls library (MSCOMCTL.OCX) that ships with Microsoft Office, classified as code injection (CWE-94). An attacker triggers it by getting a victim to open a specially crafted document or browse to a crafted web page that instantiates the control and corrupts the system state, allowing arbitrary code execution in the context of the user. Successful exploitation gives the attacker the privileges of the logged-on user, enabling malware delivery or lateral movement, which matches the weaponized-document patterns seen in APT campaigns referenced in related reporting. Any user of Microsoft Office where the vulnerable control is present and loadable from untrusted documents or web content is affected. Exploitation is confirmed in the wild: the flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) and EPSS assigns a 72.2% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept code is known. Do: Apply Microsoft's Office security updates per vendor instructions, as required by the CISA KEV catalog, and verify on legacy systems that MSCOMCTL.OCX has actually been updated rather than assumed. Restrict or prompt on ActiveX control instantiation from untrusted documents and web pages, and hunt for spearphishing documents or web content that exercises the TabStrip control, given the APT and malware-tooling activity noted in related reporting. | — | 72% | KEV |
| mass≈100M+ Office installations potentially carry the vulnerable control; actual current exposure is far lower because vendor updates have been available since… | |
| CVE-2013-0422 | Java Applet Permission-Restriction Flaw Enables Remote Code Execution in Oracle JRE CVE-2013-0422 is a flaw in how Oracle's Java Runtime Environment restricts the permissions of Java applets (CWE-264), allowing an applet to run with privileges beyond its intended security sandbox. It is triggered when a user loads a web page that delivers a malicious Java applet, such as via a drive-by visit or a phishing link pointing to an attacker-controlled site. Successful exploitation lets the attacker execute commands in the context of the current user on the client system, which in the 2013 campaigns was used to deliver malware families tracked in exploit kits and APT activity (e.g., Whitehole, Miniduke, Icefog) and is recorded by CISA as being used in ransomware. Any system with Oracle JRE installed—especially workstations and browsers with the Java applet plug-in enabled—is affected. Exploitation is confirmed in the wild: the flaw was mass-exploited by exploit kits at the time of disclosure, it carries a 97.6% EPSS probability of exploitation (100th percentile), and it was added to CISA KEV on 2022-05-25, so patching remains an active requirement. Do: Apply Oracle's Java updates per vendor instructions — at disclosure this meant the emergency Java 7 Update 11 or later, and today the current supported Java release. As interim mitigation, disable the Java browser plug-in (or Java in browsers) and uninstall JRE where it is no longer needed. Given known in-the-wild use by exploit kits and ransomware, prioritize KEV remediation and check endpoints for drive-by web-borne infections delivered via malicious applets. | — | 98% | KEV ransomware |
| masshundreds of millions of Java installs (Java was near-ubiquitous on enterprise desktops and servers in 2013) |
Full article672 words · extracted from securelist.com · click to collapse
The emergence of small groups of cyber-mercenaries available for hire to perform surgical hit and run operations.
The world of Advanced Persistent Threats (APTs) is well known. Skilled adversaries compromising high-profile victims and stealthily exfiltrating valuable data over the course of many years. Such teams sometimes count tens or even hundreds of people, going through terabytes or even petabytes of exfiltrated data.
Although there has been an increasing focus on attribution and pinpointing the sources of these attacks, not much is known about a new emerging trend: the smaller hit-and-run gangs that are going after the supply chain and compromising targets with surgical precision.
Since 2011 we have been tracking a series of attacks that we link to a threat actor called ‘Icefog’. We believe this is a relatively small group of attackers that are going after the supply chain — targeting government institutions, military contractors, maritime and ship-building groups, telecom operators, satellite operators, industrial and high technology companies and mass media, mainly in South Korea and Japan. This Icefog campaigns rely on custom-made cyber-espionage tools for Microsoft Windows and Apple Mac OS X. The attackers directly control the infected machines during the attacks; in addition to Icefog, we noticed them using other malicious tools and backdoors for lateral movement and data exfiltration.
Key findings on the Icefog attacks:
- The attackers rely on spear-phishing and exploits for known vulnerabilities (eg. CVE-2012-0158, CVE-2012-1856, CVE-2013-0422 and CVE-2012-1723). The lure documents used in the attacks are specific to the target’s interest; for instance, an attack against a media company in Japan used the following lure:

Lure document shown to the victim upon successful execution of the exploit
- Based on the profiles of known targets, the attackers appear to have an interest in the following sectors: military, shipbuilding and maritime operations, research companies, telecomoperators, satellite operators, mass media and television.
- Research indicates the attackers were interested in targeting defense industry contractors such asLig Nex1 and Selectron Industrial Company, ship-building companies such as DSME Tech, Hanjin Heavy Industries or telecom operators such as Korea Telecom.
- The attackers are hijacking sensitive documents and company plans, e-mail account credentials, and passwords to access various resources inside and outside the victim’s network.
- During the operation, the attackers are using the “Icefog” backdoor set (also known as “Fucobha”). Kaspersky Lab identified versions of Icefog for both Microsoft Windows and Mac OS X.
- While in most other APT campaigns, victims remain infected for months or even years and attackers are continuously exfiltrating data, Icefog operators are processing victims swiftly and in a surgical manner — locating and copying only specific, targeted information. Once the desired information is obtained, they abandon the infection and move on.
- In most cases, the Icefog operators appear to already know very well what they need from the victims. They look for specific file names, which are identified and transferred to the C&C.
Kaspersky Lab would like to thank KISA (Korea Internet & Security Agency) and INTERPOL for their support in this investigation.
We’re sharing Indicators of Compromise based on the OpenIOC framework for Icefog. This way organizations have an alternative way of checking their network for presence of (active) Icefog infections.
You can download the IOC file (.zip) here.
A detailed FAQ on Icefog is available.
You can read our full Icefog report here:
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/the-icefog-apt-a-tale-of-cloak-and-three-daggers/57331/
