ZeroHour
Security Affairspublished ()ingested @securityaffairs

FruityArmor APT exploited Windows Zero

criticalExploit / PoCimportance 60CVE-2016-3393

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-3393
Remote Code Execution in Microsoft Windows GDI/GDI+ Graphics Component

CVE-2016-3393 is a remote code execution vulnerability in the Windows Graphics Device Interface (GDI/GDI+), the component that renders text, images and graphics across Windows. An attacker triggers it by getting a user to visit a crafted website or otherwise view attacker-supplied content that is rendered through GDI (the CVSS vector confirms user interaction is required), and successful exploitation yields arbitrary code execution in the context of the current user. Affected software spans essentially the entire Windows estate of the era: Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507/1511/1607, and Windows Server 2008 SP2 and R2 SP1 and Server 2012 and 2012 R2. The flaw was patched in Microsoft's November 2016 Patch Tuesday, which fixed five zero-days being exploited in the wild, and reporting at the time attributed exploitation of this Windows graphics zero-day to the FruityArmor APT in targeted attacks. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25), has a high EPSS score (68.7%, 99th percentile), and no public proof-of-concept is known.

Do: Apply the November 2016 Microsoft security updates for the Windows Graphics Component to every affected Windows client and server version, per vendor instructions and CISA KEV's required action. For versions past end of support (Vista, 7, 8.1, RT 8.1, Server 2008/2012), move to a supported Windows release or apply Extended Security Updates. Until patched, discourage users from visiting untrusted websites or opening untrusted documents/images, and prioritize remediation on internet-facing servers and endpoints used by high-value users, given the documented targeted-attack use by the FruityArmor APT.

7.869% KEV
  • Microsoft Windows Vista SP2
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 all supported editions
  • +4 more
mass~hundreds of millions of Windows PCs and servers at the time of disclosure (affected versions spanned nearly the entire Windows installed base); today the…
Full article385 words · extracted from securityaffairs.com · click to collapse

A new APT group, dubbed FruityArmor, targeted activists, researchers, and individuals related to government organizations.

According to experts at Kaspersky Lab, the FruityArmor APT conducted targeted attacks leveraging on a Windows zero-day vulnerability, tracked as CVE-2016-3393, recently patched by Microsoft.

The security bulletins issued by Microsoft in October patched four zero-day flaws, including the CVE-2016-3393 one that it a remote code execution vulnerability.

FruityArmor APT zero-day

The experts have observed victims in different countries, including Iran, Algeria, Thailand, Yemen, Saudi Arabia, and Sweden.

According to Kaspersky Lab, the hackers behind FruityArmor exploited several zero-day vulnerabilities and used an attack platform built around the Microsoft PowerShell framework.

“FruityArmor is perhaps a bit unusual due to the fact that it leverages an attack platform that is built entirely around PowerShell. The group’s primary malware implant is written in PowerShell and all commands from the operators are also sent in the form of PowerShell scripts.” reads a blog post published on Thursday by Kaspersky.

Another peculiarity of the group is the use of the Windows Management Instrumentation (WMI) for persistence.

The malicious code used by the APT is hard to detect, the experts from Kaspersky highlighted that its payloads run directly in memory.

According to the experts, the FruityArmor APT group exploits the zero-day flaw for privilege escalation, that combined with browser exploits allow the attackers to escape the browser sandbox.

“To achieve remote code execution on a victim’s machine, FruityArmor normally relies on a browser exploit. Since many modern browsers are built around sandboxes, a single exploit is generally not sufficient to allow full access to a targeted machine.” reads the blog post.

“In the case of FruityArmor, the initial browser exploitation is always followed by an EoP exploit. This comes in the form of a module, which runs directly in memory. The main goal of this module is to unpack a specially crafted TTF font containing the CVE-2016-3393 exploit. After unpacking, the module directly loads the code exploit from memory with the help of AddFontMemResourceEx. After successfully leveraging CVE-2016-3393, a second stage payload is executed with higher privileges to execute PowerShell with a meterpreter-style script that connects to the C&C.” 

For further details give a look at the Kaspersky analysis.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – FruityArmor APT, Zero-day)

[adrotate banner=”5″]

[adrotate banner=”13″]

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/52504/cyber-crime/fruityarmor-apt-0day.html