ZeroHour
The Recordpublished ()ingested

Cyber agencies warn of new TrueBot malware variants targeting US and Canadian firms

highMalwareimportance 47CVE-2022-31199

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-31199
Unauthenticated Deserialization RCE in Netwrix Auditor Video Recording Component

CVE-2022-31199 is an insecure object deserialization flaw (CWE-502; CISA also tags CWE-122) in the User Activity Video Recording component of Netwrix Auditor. An unauthenticated remote attacker who can reach the component's TCP port 9004 can trigger the flaw; this port is commonly blocked by standard enterprise firewalling, which limits how many environments are directly reachable. Successful exploitation yields arbitrary code execution running as NT AUTHORITY\SYSTEM, giving the attacker full local privileges on the affected host and a strong foothold for follow-on activity such as ransomware. Any organization running Netwrix Auditor with the User Activity Video Recording component deployed is affected, with the available data providing no specific affected version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11 with known ransomware use, and EPSS assigns a 36% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

Do: Apply updates per vendor instructions immediately, or discontinue use of the affected component if updates are unavailable, per CISA's required action. Inventory whether the User Activity Video Recording component is installed and whether TCP port 9004 is reachable from user networks, VPNs, or the internet, and restrict that port to trusted hosts as a stopgap. Prioritize remediation given the KEV listing and known ransomware use.

9.836% KEV ransomware PoC
  • Netwrix Auditor
large≈10,000–100,000 installations (estimated)
Full article442 words · extracted from therecord.media · click to collapse

Cybersecurity agencies in the U.S. and Canada warned Thursday that threat actors are using new TrueBot malware variants to steal data from victims.

In an advisory co-written by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the Multi-State Information Sharing and Analysis Center (MS-ISAC), and the Canadian Centre for Cyber Security (CCCS), the organizations said that as recently as May 31 they observed a surge in financially motivated TrueBot activity.

According to the agencies, TrueBot is a botnet that has been used by groups such as the Clop ransomware gang to exfiltrate data from infected devices. The malware was developed at least as far back as 2017 by a Russian-speaking hacking group known as Silence that was involved in high-profile attacks on financial institutions.

The malware traditionally spread through malicious phishing email attachments, but the agencies said threat actors have shifted their tactics and use new variants that rely on the exploitation of a remote code execution (RCE) vulnerability affecting the Netwrix Auditor application. More than 13,000 organizations across over 100 countries use the Texas-based company's software to help with IT auditing, security and compliance, according to Netwrix’s website.

“Based on confirmation from open-source reporting and analytical findings of Truebot variants, the authoring organizations assess cyber threat actors are leveraging both phishing campaigns with malicious redirect hyperlinks and CVE-2022-31199 [the Netwrix vulnerability] to deliver new Truebot malware variants,” the agencies said.

Cybersecurity researchers started warning about increased TrueBot activity shortly after the Netwrix Auditor vulnerability was disclosed in mid-2022. Researchers at Cisco Talos wrote in December that they “noticed a small number of cases” where TrueBot was executed after hackers exploited the Netwrix vulnerability, but they said it was “unlikely that the attackers managed to compromise a high number of systems this way.”

truebot.jpg A new TrueBot botnet with over 500 infections by December 2022 was focused around the U.S. and Canada. Image: Cisco Talos

Talos researchers said they "started seeing a bigger uptick" in victims a couple months later, as hackers started using Raspberry Robin malware to deliver TrueBot to organizations mainly in Mexico, Brazil and Pakistan.

The advisory published Thursday did not name specific victims or say how many organizations have been targeted. The agencies published details about how to detect the malware and mitigate its effects, including applying patches for the Netwrix Auditor vulnerability and mandating multifactor authentication for all staff and services.

No previous article

No new articles

Adam Janofsky

is the founding editor-in-chief of The Record from Recorded Future News. He previously was the cybersecurity and privacy reporter for Protocol, and prior to that covered cybersecurity, AI, and other emerging technology for The Wall Street Journal.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cyber-agencies-warn-of-truebot-malware-variants-us-canada