US and Canadian Authorities Warn of Increased Truebot Activity
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-31199 | Unauthenticated Deserialization RCE in Netwrix Auditor Video Recording Component CVE-2022-31199 is an insecure object deserialization flaw (CWE-502; CISA also tags CWE-122) in the User Activity Video Recording component of Netwrix Auditor. An unauthenticated remote attacker who can reach the component's TCP port 9004 can trigger the flaw; this port is commonly blocked by standard enterprise firewalling, which limits how many environments are directly reachable. Successful exploitation yields arbitrary code execution running as NT AUTHORITY\SYSTEM, giving the attacker full local privileges on the affected host and a strong foothold for follow-on activity such as ransomware. Any organization running Netwrix Auditor with the User Activity Video Recording component deployed is affected, with the available data providing no specific affected version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11 with known ransomware use, and EPSS assigns a 36% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. Do: Apply updates per vendor instructions immediately, or discontinue use of the affected component if updates are unavailable, per CISA's required action. Inventory whether the User Activity Video Recording component is installed and whether TCP port 9004 is reachable from user networks, VPNs, or the internet, and restrict that port to trusted hosts as a stopgap. Prioritize remediation given the KEV listing and known ransomware use. | 9.8 | 36% | KEV ransomware PoC |
| large≈10,000–100,000 installations (estimated) |
Full article333 words · extracted from infosecurity-magazine.com · click to collapse
A warning about increased Truebot malware activity involving new tactics, techniques and procedures (TTPs) has been issued by US and Canadian authorities on July 6 2023.
The joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Multi-State Information Sharing and Analysis Center (MS-ISAC) and the Canadian Centre for Cyber Security (CCCS) noted that threat actors are leveraging newly identified Truebot malware variants to target organizations via new techniques in the US and Canada.
Truebot is known to be used by notorious cyber-criminal gangs such as Clop and Silence to collect and exfiltrate information from victims.
Read more about Clop extortion campaigns: Clop Starts MOVEit Extortion as New Bug is Discovered
The document observed that previous Truebot malware variants were primarily delivered via malicious phishing email attachments. However, the government agencies have recently noticed a shift in approach, with threat actors increasingly exploiting the CVE-2022-31199 vulnerability to leverage the botnet.
The remote code execution vulnerability is present in Netwrix Auditor, software used for on-premises and cloud-based IT system auditing. Exploiting this CVE allows attackers to gain initial access and move laterally within the compromised network.
The advisory went on to explain that once the malicious file is downloaded, Truebot renames itself and deploys FlawedGrace onto the host. This remote access tool (RAT) can then modify registry and print spooler programs, which allows it to escalate privilege and establish persistence.
The agencies added that Truebot has been observed in association with a number of other delivery malware vectors and tools, including Raspberry Robin and Colbalt Strike.
Organizations have been advised to take a number of steps to mitigate the increased threat from Truebot, including monitoring and controlling the execution of software and applying vendor patches to Netwrix Auditor.
“Any organization identifying indicators of compromise (IOCs) within their environment should urgently apply the incident responses and mitigation measures detailed in this CSA and report the intrusion to CISA or the FBI,” the advisory read.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/us-canadian-truebot-activity/