ZeroHour
Security Affairspublished ()ingested @securityaffairs

Chinese hackers behind the CNACOM campaign hit Taiwan website

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-0016
Directory Traversal Privilege Escalation in Microsoft Windows TS WebProxy

CVE-2015-0016 is a directory traversal flaw (CWE-22) in the TS WebProxy (TSWbPrxy) component that ships with Microsoft Windows. A remote attacker can submit crafted path input that the component processes without properly restricting path traversal, allowing content to be placed or retrieved outside the intended directory. Successful exploitation lets the attacker escalate privileges on the targeted Windows system. Any Windows installation containing the vulnerable TS WebProxy component is affected; the available data does not enumerate specific Windows version ranges, and Microsoft shipped the fix with its January 2015 security updates, so unpatched systems remain at risk. The flaw was added to the CISA KEV catalog on 2022-05-25, confirming known in-the-wild exploitation; EPSS is high at 75.9% (99th percentile), no public proof-of-concept is known, and any ransomware association is unknown.

Do: Apply Microsoft's January 2015 security updates (or later servicing/cumulative updates) to all Windows systems, prioritizing servers that run Remote Desktop Gateway/RD Web Access or RemoteApp and Desktop Connections where TS WebProxy is actively exercised, in line with CISA's required action to apply updates per vendor instructions. Verify the TSWbPrxy component is updated across the estate and hunt for exploitation activity on unpatched hosts; ransomware association is unknown, so treat any confirmed compromise accordingly.

76% KEV
  • Microsoft Windows
masson the order of hundreds of millions of Windows installations (TS WebProxy ships with Windows, whose installed base exceeds 1 billion devices)
CVE-2016-0189
Memory Corruption RCE in Microsoft IE Scripting Engines (JScript/VBScript)

CVE-2016-0189 is a memory corruption flaw (out-of-bounds write, per CWE-787) in Microsoft's JScript 5.8 and VBScript 5.7/5.8 scripting engines, as used in Internet Explorer 9 through 11 and other products that embed those engines. It is triggered remotely when a user is lured into viewing a crafted website that mishandles script, corrupting memory in the browser process. A successful attacker gains arbitrary code execution in the context of the current user (or can crash the browser, causing denial of service), with no authentication required but user interaction needed. Anyone running Internet Explorer 9-11 on Windows, or other products using the affected scripting engines, was exposed. Exploitation is well established: public write-ups document its use in drive-by exploit kit attacks and subsequent 'God Mode' local privilege-escalation variants, it is listed in CISA KEV (added 2022-03-28) with known ransomware use, and EPSS assigns a 94.1% probability of exploitation within 30 days.

Do: Apply the vendor-supplied Microsoft security updates for Internet Explorer and the JScript/VBScript scripting engines per CISA's required action, prioritizing endpoints used for web browsing and email since this is delivered via drive-by website attacks and is known to be used by ransomware operators. Systems that no longer receive updates for IE 9-11 should be migrated to a supported browser or OS. Check your environment against CISA KEV to confirm remediation status.

7.594% KEV ransomware PoC
  • microsoft Internet Explorer 9 through 11
  • microsoft JScript scripting engine 5.8 (as used in Internet Explorer 9-11 and other products)
  • microsoft VBScript scripting engine 5.7 and 5.8 (as used in Internet Explorer 9-11 and other products)
masshundreds of millions of Windows endpoints at disclosure (IE 9-11 shipped as the default Windows browser); residual exposure on legacy/enterprise Windows…
Full article552 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 06, 2016

Security firm Zscaler have been monitoring a cyber espionage campaign dubbed ‘CNACOM’ that was targeting government organization in Taiwan.

Security researchers from the firm Zscaler have been monitoring a cyber espionage campaign dubbed ‘CNACOM‘ that was targeting government organization in Taiwan. According to the researchers, the hackers behind the CNACOM campaign are linked to China and exploited an IE vulnerability, tracked as CVE-2016-0189, patched by Microsoft early 2016.

The CVE-2016-0189 had been exploited in targeted attacks against Windows users in South Korea before Microsoft fixed it.

In order to trigger the vulnerability, victims have to visit a compromised website or open a spear-phishing email containing a malicious link.

The threat actors used watering hole attacks to spread a malware, among the sites compromised by the hackers, there is a major public service organization in Taiwan.

Experts from startup Theori have made a reverse engineering of the MS16-053 that fixed the CVE-2016-0189 flaw and published a PoC exploit for the vulnerability.

The PoC code works on Internet Explorer 11 running on Windows 10, a great gift for fraudsters that included it in the Neutrino EK as confirmed by FireEye.

Since researchers released the full proof of concept for the CVE-2016-0189 flaw, experts at Zscaler ThreatLabZ have been closely tracking its proliferation.

The exploit code for the flaw was first spotted as part of the Sundown exploit kit (EK), later it was included in the Magnitude and the KaiXin EK.

“This blog details CNACOM, a web-based campaign that appears to be related to a well-known nation-state actor more commonly associated with spear-phishing attacks.” reads the analysis published by Zscaler. “On November 7, we spotted a malicious injection on the registration page of a major Taiwanese public service website. An iframe was injected into the footer of the page, which then loaded a unique landing page containing the CVE-2016-0189 exploit code.”

cnacom campaign

The hackers behind the CNACOM campaign used the same PoC code, but they leveraged on another Internet Explorer privilege escalation flaw, tracked as CVE-2015-0016.

The experts highlighted that that CNACOM campaign specifically targeted Taiwanese government entities. The exploit code collects information from the device, including its IP address. If the victim uses the IE and the IP address belongs to the Taiwanese government, the exploit delivers a strain of the Ixeshe malware.

The Ixeshe malware has been around since at least 2009, in August 2013 security experts at FireEye observed a series of cyber attacks conducted by the Chinese APT group known as APT12 targeting the US media. The experts linked the threat actors to the campaign that targeted the New York Times in 2012.

The variant of Ixeshe malware used in the CNACOM campaign is different from older ones.

“Unlike many historical IXESHE samples, it appears that this variant doesn’t utilize campaign codes embedded in the malware itself. This may be due to a more centralized tracking system that only relies on the malware reporting a machine ID.” continues the analysis.

Government agencies and private firms in Taiwan are often victims of cyber espionage likely launched by Chinese hackers, a few weeks ago the Tropic Trooper APT hit government Taiwanese organizations and companies in the energy sector.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Taiwan, CNACOM campaign)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/54093/intelligence/cnacom-campaign.html