ZeroHour
Security Affairspublished ()ingested @securityaffairs

Clop ransomware claims the hack of 130 orgs using GoAnywhere MFT flaw

criticalRansomware exploited in the wildimportance 60CVE-2023-0669

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-0669
Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT

Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%.

Do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use.

7.2100% KEV ransomware PoC ×3
  • Fortra GoAnywhere MFT
moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface)
Full article545 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 11, 2023

The Clop ransomware group claims to have breached over 130 organizations exploiting the GoAnywhere MFT zero-day.

The Clop ransomware group claims to have stolen sensitive data from over 130 organizations by exploiting a zero-day vulnerability (CVE-2023-0669) in Fortra’s GoAnywhere MFT secure file transfer tool, BleepingComputer reported.

Fortra immediately addressed the flaw with the release of emergency security patch and urged customers to install it.

The popular investigator Brian Krebs first revealed details about the zero-day on Mastodon and pointed out that Fortra has yet to share a public advisory.

“GoAnywhere MFT, a popular file transfer application, is warning about a zero-day remote code injection exploit. The company said it has temporarily implemented a service outage in response.” Krebs wrote on Mastodon. “I had to create an account on the service to find this security advisory”

According to the private advisory published by Fortra, the zero-day is a remote code injection issue that impacts GoAnywhere MFT. The vulnerability can only be exploited by attackers with access to the administrative console of the application.

Installs with administrative consoles and management interfaces that are not exposed on the internet are safe, however, security researcher Kevin Beaumont discovered about 1000 Internet-facing consoles.

Fortra recommends GoAnywhere MFT customers to review all administrative users and monitor for unrecognized usernames, especially those created by system.

Clop told BleepingComputer that they were able to compromise over 130 organizations in just ten days, but did not share details regarding their claims.

BleepingComputer could not independently confirm Clop's claims, and Fortra has not replied to emails asking for more info regarding CVE-2023-0669 exploitation and the ransomware group's allegations.

— BleepingComputer (@BleepinComputer) February 10, 2023

The crooks also claims to have fully compromised the network organizations, but did not deploy any ransomware.

Multiple experts already released exploits for the CVE-2023-0669 vulnerability, on February 6, 2023, the researcher Florian Hauser of IT security consulting firm Code White released a proof-of-concept (PoC) exploit code.

Ron Bowes, lead security researcher at Rapid7 announced they have merged their exploit for Fortra’s GoAnywhere MFT into Metasploit

Just merged our exploit for Fortra's GoAnywhere MFT into Metasploit, with a huge assist from @zeroSteiner! Works great against Linux and Windows targets.

There's a patched version out now, make sure you've updated!https://t.co/vY3gLTisXh

— Ron Bowes (@iagox86) February 8, 2023

Researchers at threat intelligence firm Huntress shared findings of their investigation into GoAnywhere MFT exploitation and linked the attacks to the TA505 threat actors.

“While links are not authoritative, analysis of Truebot activity and deployment mechanisms indicate links to a group referred to as TA505Distributors of a ransomware family referred to as Clop, reporting from various entities links Silence/Truebot activity to TA505 operations.” reads the analysis published by Huntress. “Based on observed actions and previous reporting, we can conclude with moderate confidence that the activity Huntress observed was intended to deploy ransomware, with potentially additional opportunistic exploitation of GoAnywhere MFT taking place for the same purpose.”

This week CISA also added the GoAnywhere MFT flaw to its  Known Exploited Vulnerabilities Catalog, ordering federal agencies to address it by March 3, 2023.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Clop ransomware)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/142130/cyber-crime/clop-ransomware-goanywhere-mft.html