ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Pawn Storm’s Stealthy Net

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-23397
Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak)

CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates.

Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook.

9.897% KEV
  • Microsoft 365 Apps Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Long Term Servicing Channel (LTSC) Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • +1 more
masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite)
CVE-2023-38831
Code Execution in RARLAB WinRAR via Crafted ZIP File/Folder Name Confusion

RARLAB WinRAR before 6.23 mishandles ZIP archives that contain a benign file (such as a JPG) alongside a folder with the same name, causing the folder's contents - which can include malicious executable files - to be processed when the user merely attempts to view the benign file. By sending a crafted ZIP archive, an attacker gains arbitrary code execution on the victim's machine with the user's privileges. Because the flaw is local (AV:L) and requires user interaction, risk is limited to Windows systems running an unpatched copy of WinRAR, while machines without the tool are unaffected. The bug was actively exploited in the wild from April through October 2023, including by government-backed actors (APT28), SideCopy attacks on Indian government entities, ransomware operations, and trading-account theft campaigns, and it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-08-24.

Do: Upgrade all Windows systems running WinRAR to version 6.23 or later, which fixes this flaw; if patching is not immediately possible, treat ZIP files from untrusted sources with caution and check archives for duplicate file/folder names before opening. Given KEV listing with known ransomware use and public proof-of-concept exploits, hunt for compromise by reviewing whether unexpected executables or scripts ran when ZIP archives were opened, and apply vendor mitigations per CISA's required action or discontinue use if mitigations are unavailable.

7.898% KEV ransomware PoC ×4
  • RARLAB WinRAR before 6.23
masshundreds of millions of users/installations worldwide (WinRAR is one of the most widely installed Windows archive utilities)

Indicators of compromiseAll →

TypeIndicatorContext
domainwebhook.sitepaign in late 2023 targeted European governments, utilizing webhook[.]site URLs and VPN IP addresses. In October 2022, Pawn Storm em
Full article406 words · extracted from infosecurity-magazine.com · click to collapse

Pawn Storm, an advanced persistent threat (APT) actor also known as APT28, has been targeting high-value entities globally, employing a range of techniques since at least 2004. 

Despite relying on seemingly outdated methods like decade-old phishing campaigns, the group continues to compromise thousands of email accounts. 

According to an advisory published today by Trend Micro researchers Feike Hacquebord and Fernando Merces, the group has recently been involved in Net-NTLMv2 hash relay attacks, attempting to brute-force its way into government, defense and military networks worldwide.

Between April 2022 and November 2023, Pawn Storm reportedly focused on launching NTLMv2 hash relay attacks, targeting government departments dealing with foreign affairs, energy, defense, transportation and various other sectors. 

The group was active in Europe, North America, South America, Asia, Africa and the Middle East. It demonstrated persistence by modifying folder permissions in victims’ mailboxes, enabling lateral movement.

Pawn Storm has enhanced its operational security in recent years, gradually changing its tactics. Brute-force credential attacks on mail servers and corporate VPN services have been common since 2019. 

Read more about Pawn Storm: Russian APT28 Group Changes Tack to Probe Email Servers

In recent years, the group has also employed anonymization layers like VPN services, Tor, compromised EdgeOS routers and free services such as URL shorteners. The use of anonymization layers extends to spear-phishing emails sent from compromised email accounts accessed over Tor or VPN exit nodes.

A critical vulnerability, CVE-2023-23397, patched in March 2023, allowed Pawn Storm to conduct hash relay attacks on Outlook users. Exploiting this flaw, the group sent malicious calendar invites, triggering the Net-NTLMv2 hash relay attack.

The campaign extended to August 2023, evolving with more elaborate methods, including scripts hosted on Mockbin and URLs redirecting to PHP scripts on free web hosting domains.

Pawn Storm’s diversification includes using the WinRAR vulnerability CVE-2023-38831 for hash relay attacks. A credential phishing campaign in late 2023 targeted European governments, utilizing webhook[.]site URLs and VPN IP addresses.

In October 2022, Pawn Storm employed an information stealer without a command-and-control (C2) server. This crude yet effective method involved uploading stolen files to a free file-sharing service, using shortened URLs for access.

In the Trend Micro advisory, Hacquebord and Merces warned that Pawn Storm remains aggressive despite its two-decade history, adapting loud and aggressive tactics alongside advanced and stealthy methods. 

Network defenders are urged to leverage indicators of compromise provided in the research to bolster their security against Pawn Storm’s persistent threats.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/pawn-storms-stealthy-net-ntlmv2/