ZeroHour
Security Affairspublished ()ingested @securityaffairs

HelloKitty ransomware gang targets vulnerable SonicWall devices

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-7481
Unauthenticated SQL Injection in SonicWall SMA100 Appliances

SonicWall SMA100 secure-access appliances contain a SQL injection flaw (CWE-89) that requires no authentication to exploit. A remote attacker sends crafted input to the vulnerable appliance, most plausibly through its internet-facing web/remote-access interface, and gains read-only access to resources they are not authorized to see. An attacker is therefore limited to reading unauthorized data, but the flaw provides unauthenticated access to a network edge device and a basis for further reconnaissance. Any organization running a SonicWall SMA100 appliance — typically deployed as an internet-exposed SSL-VPN/remote-access gateway — is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with ransomware use noted, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile).

Do: Apply firmware updates to SMA100 appliances per SonicWall's instructions, as CISA's required action states and no fixed version is given in this data. Because CISA notes known ransomware use, prioritize patching any internet-exposed SMA device, review appliance and firewall logs for unexpected unauthenticated access, and as an interim mitigation restrict exposure of the appliance's web interface to trusted source addresses.

7.5100% KEV ransomware
  • SonicWall SMA100
largeon the order of tens of thousands of internet-exposed SMA100/SSL-VPN appliances
CVE-2021-20016
Unauthenticated SQL Injection in SonicWall SMA100 SSL VPN

CVE-2021-20016 is an unauthenticated SQL injection flaw (CWE-89) in the SonicWall SSL-VPN service on SMA 100 appliances. It is triggered remotely by malicious, unauthenticated requests to the appliance's web interface, allowing SQL injection against the backend database. Successful exploitation gives the attacker credential access — harvesting valid user credentials that can then be used to log into the SSL-VPN and pivot into the victim network. Any organization running an internet-facing SonicWall SSLVPN SMA100 appliance is affected, and CISA notes known ransomware use of this flaw. It was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 40% EPSS probability of exploitation within 30 days (99th percentile), so it should be treated as actively exploited even though no public proof-of-concept is known.

Do: Apply the SonicWall firmware update per vendor instructions, as required by the CISA KEV listing. Because ransomware operators are known to exploit this flaw, review SMA100 authentication and admin logs for unfamiliar logins, rotate exposed credentials, and restrict the appliance to trusted source IPs until it is patched. CVSS has not yet been scored, but the 40% EPSS (99th percentile) and KEV status warrant immediate patching of all internet-exposed units.

9.840% KEV ransomware
  • SonicWall SSLVPN SMA100
large≈ tens of thousands of internet-exposed SMA100 appliances (public scan counts of SonicWall SSL-VPN endpoints)
Full article367 words · extracted from securityaffairs.com · click to collapse

BleepingComputer became aware that the recent wave of attacks targeting vulnerable SonicWall devices was carried out by HelloKitty ransomware operators.

SonicWall this week has issued an urgent security alert to warn companies of “an imminent ransomware campaing” targeting some of its equipment that reached end-of-life (EoL).

Threat actors could target unpatched devices belonging to Secure Mobile Access (SMA) 100 series and Secure Remote Access (SRA) families.

“Through the course of collaboration with trusted third parties, SonicWall has been made aware of threat actors actively targeting Secure Mobile Access (SMA) 100 series and Secure Remote Access (SRA) products running unpatched and end-of-life (EOL) 8.x firmware in an imminent ransomware campaign using stolen credentials.” reads the alert published by the company. “The exploitation targets a known vulnerability that has been patched in newer versions of firmware.”

The company states that organizations that fail to address known vulnerabilities in the firmware of SRA and SMA 100 series products are at imminent risk of a targeted ransomware attack.

The network equipment vendor is now urging customers to update the firmware of their devices as soon as possible.

CISA also warned of ransomware attacks attempting to exploit known, previously patched, vulnerability in SonicWall Secure Mobile Access (SMA) 100 series and Secure Remote Access (SRA) products.

Both SonicWall and CISA did not provide details about the threat actors behind these attacks, but BleepingComputer became aware that HelloKitty ransomware gang has been exploiting the issue in a recent wave of attacks.

“While CISA and SonicWall did not reveal the identity of the threat attackers behind these attacks, BleepingComputer was told by a source in the cybersecurity industry that HelloKitty has been exploiting the vulnerability for the past few weeks.” reported BleepingComputer.

Bleeping computer also added that CrowdStrike confirmed that several three actors, including HelloKitty ransomware operators, are attempting to exploit a flaw tracked as CVE-2019-7481.

Other groups targeted known vulnerabilities in SonicWall devices in the past, such as the UNC2447 cybercrime gang that exploited the CVE-2021-20016 zero-day bug in SonicWall SMA 100 Series VPN appliances to deliver the FiveHands ransomware.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, HelloKitty ransomware)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/120249/malware/hellokitty-ransomware-sonicwall-devices.html