ZeroHour
Security Affairspublished ()ingested @securityaffairs

Malaysia MyCERT warns cyber espionage campaign carried out by APT40

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-6352
Remote Code Execution in Microsoft Windows via Crafted OLE Objects (CVE-2014-6352)

CVE-2014-6352 is a code injection vulnerability (CWE-94) in the way Microsoft Windows processes Object Linking and Embedding (OLE) objects, the mechanism used to embed linked or embedded content such as links, charts, or multimedia inside documents. An attacker triggers the flaw by delivering a file containing a crafted OLE object — typically an Office document such as a presentation — and persuading a user to open it; successful exploitation allows the attacker to execute arbitrary code in the context of the logged-in user, potentially giving them control of the endpoint for data theft or as a foothold for lateral movement. The vulnerability affects Microsoft Windows systems for which Microsoft shipped fixes in its November 2014 updates, so any unpatched or legacy Windows client or server remains exposed. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-25), confirming it has been used in real-world attacks, and its EPSS score of 77.6% places it in the top percentile for likely exploitation; no public proof-of-concept is recorded in the current data.

Do: Apply Microsoft's November 2014 security updates addressing this Windows OLE vulnerability across all Windows clients and servers per vendor instructions, prioritizing legacy and internet-reachable systems. Inventory the estate for missing patches, and in the interim restrict users from opening untrusted Office documents and email attachments, since exploitation requires the file to be opened. Track the CISA KEV required action and confirm remediation evidence for this entry.

78% KEV
  • Microsoft Windows
masshundreds of millions of Windows installations worldwide (Windows is near-universal on enterprise desktops and servers)
CVE-2017-0199
Remote Code Execution in Microsoft Office and WordPad via crafted document files

CVE-2017-0199 is a remote code execution vulnerability in Microsoft Office and WordPad that stems from improper parsing of specially crafted files. Attackers trigger it by getting a user to open a malicious document, after which attacker-controlled code executes with the privileges of the logged-in user. Anyone running the affected Microsoft Office or WordPad software is exposed, and CISA notes the flaw has been leveraged in ransomware campaigns; no CVSS score is available in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), indicating active, ongoing exploitation.

Do: Apply Microsoft's security updates for Office and Windows per vendor instructions, as required by CISA's KEV catalog; the flaw was publicly reported as fixed in Microsoft's April 2017 security updates. Until patched, treat unsolicited Office documents and email attachments as high-risk, since exploitation requires a user to open a crafted file. Verify that all Office and WordPad installations across the estate—especially endpoints that handle untrusted documents—have received the update.

7.8100% KEV ransomware PoC ×6
  • Microsoft Office
  • Microsoft WordPad
masshundreds of millions of Office installations worldwide (exact count unknown)
Full article423 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 10, 2020

Malaysia’s MyCERT issued a security alert to warn of a hacking campaign targeting government officials that was carried out by the China-linked APT40 group.

Malaysia’s Computer Emergency Response Team (MyCERT) warns of a cyber espionage campaign carried out by the China-linked APT40 group aimed at Malaysian government officials.

The attackers aimed at stealing confidential documents from government systems after having infected them with malware.

“MyCERT observed an increase in number of artifacts and victims involving a campaign against Malaysian Government officials by a specific threat group.” reads the alert issued by MyCERT. “The group motives is believe to be  data theft and exfiltration.”

The attackers used spear-phishing messages sent to government officials, they posed as a journalist, an individual from a trade publication, or individuals from a relevant military organization or non-governmental organization (NGO).

The messages contained links to weaponized Office documents stored on Google Drive. Once the documents are opened and the victims have enabled the macros, the dropper is executed.

The attackers exploit the CVE-2014-6352 and CVE-2017-0199 Office vulnerabilities to drop and execute the malware on the victim’s computer.

“The group’s operations tend to target government-sponsored projects and take large amounts of information specific to such projects, including proposals, meetings, financial data, shipping information, plans and drawings, and raw data,” continues MyCERT.

It is not clear if the attackers have exfiltrated sensitive documents from government officials.

The advisory doesn’t explicitly attribute the campaign to the Chinese APT, but references included in the alert point to the APT40 hacking group.

APT40

Experts believe that APT40 is a state-sponsored Chinese APT group due to its alignment with Chinese state interests and technical artifacts suggesting the actor is based in China.

The APT40 group has been active since at least 2013 and appears to be focused on supporting naval modernization efforts of the Government of Beijing. Threat actors target engineering, transportation, and defense sectors, experts observed a specific interest in maritime technologies.

The cyberspies also targeted research centres and universities involved in naval research with the intent to access advanced technology to push the growth of the Chinese naval industry.

The list of victims of the APT40 group also includes organizations with operations in Southeast Asia or involved in South China Sea disputes.

In January, a group of anonymous security researchers that calls itself Intrusion Truth has discovered that the APT40 uses 13 front companies operating in the island of Hainan to recruit hackers.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – APT40, China)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/97582/apt/malaysias-mycert-apt40-attacks.html