ZeroHour
CyberScooppublished ()ingested @shanvav

Emerging hacking tool 'EtterSilent' mimics DocuSign, researchers find

criticalRansomware exploited in the wildimportance 60CVE-2017-8570

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-8570
Remote Code Execution in Microsoft Office via Malicious PPSX Files (CVE-2017-8570)

CVE-2017-8570 is a remote code execution vulnerability in Microsoft Office caused by improper handling of embedded OLE objects (composite monikers) in memory, and it is tracked separately from the related CVE-2017-0243. An attacker triggers it by embedding a crafted moniker object in a document, most commonly a PowerPoint .ppsx slide-show file, and persuading a user to open it; the CVSS vector confirms user interaction is required. Successful exploitation lets the attacker run arbitrary code with the victim's privileges, enabling malware delivery, data theft, and follow-on activity. Any user or organization running affected Office builds that open untrusted documents is in scope, and public reporting ties the bug to high-volume maldoc toolkits (e.g., EtterSilent, ThreadKit) and targeted attacks, including one against Ukrainian organizations. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2022-02-25, EPSS puts the 30-day exploitation probability at 89.9% (100th percentile), and public PoCs exist.

Do: Apply Microsoft's June 2017 (or later) security updates to all Office installations and audit the estate for outdated builds, since CISA KEV and EPSS data show this bug is still exploited years after the patch. As an interim mitigation, block or sandbox .ppsx (PowerPoint Show) email attachments, which are the primary delivery vector, and warn users about Office files triggering embedded object content. Prioritize remediation per CISA's KEV required action: apply updates per vendor instructions.

7.890% KEV PoC ×2
  • Microsoft Office
masshundreds of millions of users potentially affected (Office install base exceeds 1 billion; practical exposure limited to systems not updated since mid-2017)
Full article591 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The tool is the latest evidence that the hacking economy is a commodity market.

(Getty Images)

Hackers are using a new, malleable malicious document builder to run their criminal schemes, according to Intel 471 research published Tuesday.

The document builder, known as EtterSilent, has been advertised in a Russian cybercrime forum and comes in two versions, according to the research. One exploits a vulnerability in Microsoft Office, CVE-2017-8570, and one uses a malicious macro.

One version of EtterSilent imitates the digital signature product DocuSign, though when targets click through to electronically sign documents, they are prompted to enable macros. This allows the attackers to target victims with malware.

EtterSilent also offers another benefit for criminals looking for the latest tools to run their schemes — the malicious document builder has been crafted to conceal the activities of its operators, and has been constantly updated in recent months to avoid detection, according to Intel 471.

The widespread use of EtterSilent shows how commoditization is a big part of the cybercrime economy,” the researchers note in a blog on the matter. “Different players specialize in their respective area, whether that be robust hosting, spam infrastructure, maldoc builders, or malware as a service, and find ways to leverage each other’s products in services by working together.”

Last month EtterSilent was used in a campaign that leveraged another tool, called Bazar loader, against targets, which can help attackers infect victims with other malware or ransomware, according to the research.

In another campaign that’s used EtterSilent, attackers dropped an updated version of Trickbot, a banking trojan that has been associated with ransomware infections. The attackers duped targets by sending emails purporting to contain invoices from a manufacturing company.

Other campaigns using banking trojans BokBot, Gozi ISFB and QBot have also used EtterSilent, Intel 471 notes.

The maldoc builder may be of interest to the U.S. government, which has been working to tamp down on infections run by Trickbot in recent months. Last year the Department of Defense’s Cyber Command, its offensive arm focused on disrupting hackers abroad, ran a campaign to disrupt Trickbot. The private sector also joined the action, with Microsoft and other private sector entities running a separate takedown of Trickbot.

But the botnet, a collection of zombie computers controlled by attackers, has continued to resurface despite their best efforts.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/docusign-security-hack-ettersilent-intel471/