ZeroHour
CyberScooppublished ()ingested @jeffstone500

Meet Sodinokibi, a ransomware strain that exploits a critical Oracle server flaw

criticalRansomware exploited in the wildimportance 60CVE-2019-2725

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-2725
Unauthenticated Injection in Oracle WebLogic Web Services Enables RCE

CVE-2019-2725 is an easily exploitable injection flaw (CWE-74) in the Web Services subcomponent of Oracle WebLogic Server within Oracle Fusion Middleware, publicly documented as affecting WebLogic 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.3. It is triggered when an unauthenticated remote attacker sends attacker-controlled XML over HTTP to the WebLogic Web Services async response endpoint (the /_async/AsyncResponseService servlet), which processes the input unsafely. Successful attacks give the attacker takeover of the affected WebLogic server (remote code execution); in the 2019 exploitation wave this was used to install cryptocurrency miners and deploy ransomware. Any organization running affected Oracle WebLogic Server versions is exposed, with the greatest risk where the async/Web Services endpoints are reachable, especially on internet-facing servers. Exploitation is confirmed in the wild: CISA added the CVE to its KEV catalog on 2022-01-10 with ransomware use known and requires applying vendor updates, the EPSS probability of exploitation is 100% (100th percentile), and no public PoC is catalogued.

Do: Apply Oracle's updates per vendor instructions: this CVE was fixed by Oracle's April 2019 out-of-band WebLogic patch and is covered by subsequent Critical Patch Updates, so bring affected WebLogic 10.3.6.0/12.1.3.0/12.2.1.x servers to a patched level (CISA KEV requires this action). Until patched, restrict or remove the async response service deployments (wls9_async_response.war / wls_wsee_async_response.war, exposing the /_async/AsyncResponseService endpoint) and keep WebLogic ports off the internet. Also review logs for unsolicited POSTs to /_async/AsyncResponseService and for signs of dropped miners or ransomware payloads.

9.8100% KEV ransomware PoC
  • Oracle WebLogic Server (Oracle Fusion Middleware, Web Services subcomponent)
largetens of thousands of internet-exposed WebLogic servers (~30,000+ reported in 2019 internet scans), plus a much larger internal install base
Full article570 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Digital extortionists are exploiting a bug with a severity score of 9.8 out of 10 that Oracle sought to squash with a patch issued last week.

Oracle, RSA 2019
(Scoop News Group photo)

Hackers are exploiting a critical vulnerability in a widely used Oracle service to distribute a new strain of ransomware that attempts to encrypt data in a user’s directory, then make recovery more difficult by deleting trustworthy backups, according to research published Tuesday.

Attackers are trying to infect victims with a new variant of the Sodinokibi ransomware by leveraging a known security flaw in Oracle’s WebLogic Server, according to Cisco’s Talos threat research team. The digital extortionists are exploiting the flaw known as CVE-2019-2725, a bug with a severity score of 9.8 out of 10 that Oracle sought to squash with a patch issued April 26, outside the company’s normal patch cycle.

“Historically, most varieties of ransomware have required some form of user interaction, such as a user opening an attachment to an email message, clicking on a malicious link, or running a piece of malware on the device,” Cisco’s Talos team wrote in a blog post. “In this case, the attackers simply leveraged the Oracle WebLogic vulnerability, causing the affected server to download a copy of the ransomware,” encrypting a number of companies without any such interaction.

WebLogic Server is a popular Java-based tool typically used by businesses to support enterprise apps. Hackers have been increasingly interested in it over the past year, perhaps because Oracle’s next security update is not scheduled until July, and more than 36,000 publicly accessible servers remain vulnerable to attack, ZDNet reported last week.

After installing the Sodinokibi ransomware — and typically charging roughly $2,500 in bitcoin to decrypt the files — attackers then attempt to launch a strain of the GandCrab ransomware, perhaps because “the attackers felt their earlier attempts had been unsuccessful and were still looking to cash in by distributing Gandcrab,” researchers speculated.

WebLogic Servers have been especially popular among hackers trying to carry out their own illicit cryptomining operations. Researchers at TrendMicro, for instance, have found numerous cases last year in which scammers mined for Monero after carrying out an attack on WebLogic targets.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/meet-sodinokibi-ransomware-strain-exploits-critical-oracle-server-flaw/