ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

The Hottest Malware Hits of the Summer

criticalMalwareimportance 60CVE-2018-8453

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-8453
Win32k Elevation of Privilege Flaw in Windows 7-10 and Windows Server (CVE-2018-8453)

CVE-2018-8453 is an elevation of privilege vulnerability in the Windows Win32k kernel component, which fails to properly handle objects in memory, including the Win32k user-callback path reachable via NtUserSetWindowFNID. An attacker who can already execute code on an affected machine can trigger the flaw to escalate privileges, gaining the equivalent of SYSTEM-level rights with high impact on confidentiality, integrity, and availability. All broadly deployed Windows releases of the era are affected, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 1809), and Windows Server 2008 through 2019, so any unpatched Windows desktop or server is in scope. The flaw was exploited as a zero-day by the FruityArmor APT in targeted attacks in the Middle East, disclosed and patched in Microsoft's October 2018 Patch Tuesday, and has public proof-of-concept code. It is confirmed exploited in the wild: it sits in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-21) with known ransomware use, and EPSS assigns a 70% probability of exploitation within 30 days.

Do: Apply Microsoft's October 2018 (or later) cumulative security updates to all affected Windows 7/8.1/RT 8.1/Windows 10 clients and Windows Server 2008-2019 systems, per the vendor instructions required by CISA's KEV catalog. Prioritize multi-user hosts such as terminal/RDS servers and workstations where users can run untrusted code, since the attack requires local code execution with user interaction. Systems still on Windows 7/8.1 or Server 2008/2008 R2/2012 should be moved to Extended Security Updates or upgraded, and defenders should hunt for signs of FruityArmor-style activity on long-lived unpatched hosts.

7.870% KEV ransomware PoC ×2
  • microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809
  • microsoft Windows 7 all supported releases as listed by Microsoft
  • microsoft Windows 8.1 all supported releases as listed by Microsoft
  • +6 more
masshundreds of millions to ~1 billion+ Windows installations (Windows 10 alone ran on roughly 700 million active devices in 2018)
Full article924 words · extracted from thehackernews.com · click to collapse

It's been a summer of ransomware hold-ups, supply chain attacks and fileless attacks flying under the radar of old-school security. With malware running amok while we were lying on the beach, here's a recap of the most burning strains and trends seen in the wild during the months of July and August 2019.

Malware Evolution Trends

The heat must have had an effect as this summer saw malware continuing to evolve, particularly around three core trends:

Evasion-by-design

Malware has been increasingly designed to bypass security controls leveraging a host of tactics, most notably by:

  • Changing hashes via file obfuscation to evade AVs.
  • Using encrypted communication with C2 servers to foil EDRs.
  • Using feature manipulation and tampering to trick AI, machine-learning engines, and sandboxes through the detection of such environments and the deliberate delay in execution.

Fileless Attacks and Living-Off-The-Land (LOTL)

Taking evasion techniques one step further, an increasing number of strains are leveraging PowerShell commands and masquerading as legitimate system tools, all while running completely from memory (RAM) to fly under the radar of traditional IoC-based solutions and requiring behavior-based analysis to detect.

(Jack-in-the-box)2 or Jack-in-the-box, Squared

No thanks to underground botnet-as-a-service businesses, whole botnets of compromised systems are rented out to hackers, through which they can leverage ready-made access to live and well systems to simultaneously unleash multiple malware strains at their disposal. For example, Emotet serving IcedID (Bokbot) followed by Trickbot or the Ryuk ransomware.

Deadliest Immediate Threats

What were this summer's most exotic and lethal malware strains? Here's a roundup.

Astaroth Malware Uses Living-Off-The-Land (LOTL) Techniques

Targeting European and Brazilian organizations, and posing an immediate threat to 76% of organizations who tested their resilience to it, according to the Cymulate Research Lab, the fileless Astaroth malware evades traditional IoC-based security controls, stealing user credentials, including PII, system and financial data.

The Hacker News
Credit: Microsoft

At no point during the entire attack kill chain does Astaroth drop any executable files on disk, or use any file that is not a system tool, running its payload completely in memory (RAM).

Sodinokibi Exploits a CVE to Push Ransomware Via MSP websites

The Sodinokibi ("Sodi") ransomware is rare in its usage of a Windows vulnerability, namely CVE-2018-8453 patched by Microsoft last year, which enables gaining admin-level access. Suspected to be the successor of the GandCrab ransomware-as-a-service, Sodinokibi is disseminated through managed service providers' (MSP) websites, a form of supply chain attacks, where download links are replaced with the ransomware executable. Initially suspected as being offered as a service in the underground because of its 'master encryption key' approach, it has been confirmed that this is, in fact, the case.

— Damian (@Damian1338) August 28, 2019

The good news is that none of the organizations simulating this specific variant were found to be vulnerable; however, the exposure rate for other Sodi variants during this summer ranged between 60% and 77%, depending on the strain tested.

GermanWiper Ransomware Adds Insult to Injury

Targeting German-speaking countries, GermanWiper does not really encrypt files. Rather, it overwrites all the victim's content with zeroes, irreversibly destroying their data. The ransom note is therefore bogus, rendering any payments made useless, and making offline backups crucial for recovery.

Posing as a job application with a CV attachment, the malware is spread via email spam campaigns. 64% of organizations simulating GermanWiper appeared to be vulnerable when testing controls against it.

MegaCortex Ransomware Extorts US and EU-based Enterprises

Posing a threat to 70% of organizations, based on attack simulations performed, MegaCortex deliberately targets larger firms in a bid to extort larger sums of cash, ranging from $2M-$6M in bitcoin. The MegaCortex operators compromise servers critical to businesses and encrypt them and any other systems connected to the host.

This ransomware was originally executed using a payload encrypted with a password that was manually entered during a live infection. In its newer strain, this password is hardcoded along with other features that have been automated, such as security evasion techniques. The malware has also evolved to decrypt and run its payload from memory.

Silence APT Spreads Malware Targeting Banks Worldwide

The Russian-speaking advanced persistent threat (APT) group is one of the most sophisticated in the world and has recently updated its TTPs to encrypt critical strings, including commands issued to bots in order to evade detection. Initially sending recon emails to potential victims to identify the easy-clickers, after initial infection, the hackers now spread additional malware to victims either through their rewritten TrueBot loader or through a fileless loader called Ivoke, hiding C2 communications through DNS tunneling. Over the past year, the group has amassed an estimated $4 million.

84% of organizations are vulnerable to the strain released this summer, according to Cymulate data.

Turla Attacks Govt's using Hijacked Oilrig APT Group's Servers

Specifically targeting governments and international bodies, Turla was seen to hijack infrastructure belonging to the Iranian-linked Oilrig APT group. Using a combination of custom malware, modified versions of publicly-available hacking tools and legitimate admin software, the group has been moving towards LOTL techniques, and its victims include ministries, governments, and communications technology organizations in ten different countries.

70% of organizations were found vulnerable to this threat at the time of security testing.

Looking to assess your organization's security posture now that the summer is over? Explore how breach and attack simulation can provide you with the immediate, actionable insights you need.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/09/its-been-summer-of-ransomware-hold-ups.html