Australian ACSC 's report confirms the use of Chinese malware in recent attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-11317 +1 in the same advisory: …11357 | Unrestricted File Upload / RCE in Progress Telerik UI for ASP.NET AJAX Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and in R2 releases before R2 2017 SP2 uses weak encryption for the RadAsyncUpload component, allowing unauthenticated remote attackers to forge upload parameters, upload arbitrary files to the web server, and ultimately execute arbitrary code. The flaw is triggered simply by sending crafted requests to the vulnerable upload handler over the network, with no authentication or user interaction required. Successful exploitation gives an attacker arbitrary file upload and remote code execution in the context of the ASP.NET application, which is typically hosted on IIS web servers. Any site or application built with Telerik UI for ASP.NET AJAX is affected, and the weakness is confirmed exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-11, and related reporting describes multiple hacking groups — including IIS/ASP.NET-focused APT actors — breaching a U.S. federal agency through it. Do: Upgrade Telerik UI for ASP.NET AJAX to R1 2017 or R2 2017 SP2 (or later) per vendor instructions, and verify the deployed Telerik.Web.UI.dll version in each application's bin folder. Given active in-the-wild exploitation of IIS/ASP.NET applications, review affected web servers for unauthorized uploads and web shells and rotate ASP.NET machine keys used with RadAsyncUpload. | 9.8 | 84% | KEV PoC ×2 |
| large≈tens of thousands of internet-exposed ASP.NET/IIS applications; the total installed base (including internal apps) is plausibly far larger | |
| CVE-2017-9248 | Cryptographic key leak (CWE-522) in Progress Telerik UI for ASP.NET AJAX & Sitefinity Progress Telerik UI for ASP.NET AJAX (Telerik.Web.UI.dll) before R2 2017 SP1 and Progress Sitefinity before 10.0.6412.0 fail to adequately protect the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey (CWE-522, insufficient key/credential protection). A remote, unauthenticated attacker can send crafted requests to the component's encrypted dialog-parameter handler to recover the dialog encryption key and then leak the MachineKey, and a public proof-of-concept exists (Exploit-DB 43873). With the MachineKey in hand, the attacker can forge or decrypt ASP.NET ViewState, upload or download arbitrary files, and inject XSS, which on IIS servers commonly chains to remote code execution via malicious ViewState. Any website or application embedding the vulnerable Telerik UI assembly, including older Sitefinity CMS releases, is affected. The flaw is confirmed exploited in the wild: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 75.1% EPSS score (99th percentile), and its use in ransomware campaigns is unknown. Do: Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP1 or later and Sitefinity to 10.0.6412.0 or later per vendor instructions, as required by CISA's KEV listing. After patching, rotate the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey, because keys leaked before patching remain usable to forge ViewState. Review IIS logs for requests to Telerik dialog handler endpoints and for unexpected file uploads, downloads, or ViewState-related anomalies. | 9.8 | 75% | KEV PoC |
| largetens of thousands of internet-exposed vulnerable installations (estimate) | |
| CVE-2019-0604 | RCE in Microsoft SharePoint via Application Package Markup Validation Flaw Microsoft SharePoint fails to check the source markup of an application package, an improper input validation flaw (CWE-20) that allows maliciously crafted markup to be processed by the server. An attacker triggers the flaw by getting an affected SharePoint server to handle a crafted application package, without any special privileges described in the disclosure. Successful exploitation lets the attacker run remote code in the context of the SharePoint application pool and the SharePoint server farm account, providing control of the web server and access to a highly privileged farm-level identity. Any organization running an affected on-premises Microsoft SharePoint deployment is exposed, with internet-facing SharePoint servers at greatest risk. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and EPSS puts the probability of exploitation at 99.9%, although no public proof-of-concept is catalogued. Do: Apply Microsoft's SharePoint security updates per vendor instructions immediately, prioritizing internet-exposed SharePoint servers as CISA's required action directs. Given known in-the-wild and ransomware use, hunt for signs of compromise such as unexpected .aspx or webshell files in SharePoint directories and anomalous use of the SharePoint farm account. Restrict or firewall internet exposure of SharePoint servers until patches are confirmed applied. | 9.8 | 100% | KEV ransomware |
| mass≈ hundreds of thousands of on-prem SharePoint server deployments worldwide, of which tens of thousands are directly internet-facing (estimate) | |
| CVE-2019-18935 | Unauthenticated .NET Deserialization RCE in Progress Telerik UI for ASP.NET AJAX CVE-2019-18935 is a .NET deserialization flaw (CWE-502) in the RadAsyncUpload function of Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023. It is triggered when an attacker who knows the Telerik upload encryption keys — most commonly because the earlier flaws CVE-2017-11317 or CVE-2017-11357 exposed them, though keys can be obtained by other means — sends crafted serialized data to RadAsyncUpload, allowing remote code execution without authentication. Successful exploitation gives an attacker arbitrary code execution on the hosting IIS/ASP.NET web server, reflected in the critical 9.8 CVSS score. Any web application built with Telerik UI for ASP.NET AJAX at or below 2019.3.1023 is affected, unless 2019.3.1023 has the non-default hardening setting enabled (as of 2020.1.114 a default setting prevents the exploit). Exploitation is rampant in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, carries a 99.7% EPSS probability of exploitation, has multiple public exploits (Bishop Fox, RAU_crypto, noperator), and has been used by multiple threat groups — including ransomware and government-linked actors — to breach organizations including a U.S. federal agency. Do: Upgrade to Progress Telerik UI for ASP.NET AJAX 2020.1.114 or later, where a default setting prevents exploitation (or, if staying on 2019.3.1023, enable the non-default hardening setting); per CISA KEV, apply updates per vendor instructions. Because exploitation requires the encryption keys to be known, also patch the older CVE-2017-11317/CVE-2017-11357 key-disclosure flaws or rotate the Telerik upload encryption keys. Check internet-facing IIS/ASP.NET applications for exposed RadAsyncUpload handlers and indicators of compromise, given known ransomware and federal-agency breaches. | 9.8 | 100% | KEV ransomware PoC ×4 |
| largeTens of thousands of internet-exposed ASP.NET/IIS web applications using Telerik controls (order-of-magnitude estimate) | |
| CVE-2019-19781 | Unauthenticated path traversal RCE in Citrix ADC, Gateway, and SD-WAN WANOP CVE-2019-19781 is a path-traversal flaw (classified CWE-22, though CISA's description calls it unspecified) in Citrix ADC (formerly NetScaler ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances that lets an unauthenticated remote attacker traverse directories via crafted requests and execute arbitrary commands on the appliance, typically with root privileges. It is triggered by sending specially crafted directory-traversal requests (crafted URLs/requests to the appliance's management or VPN endpoints), which lets the attacker write files and run commands with no credentials. Successful exploitation yields arbitrary code execution on the appliance, enabling theft of VPN/ADC credentials, lateral movement into the corporate network, and installation of persistent backdoors. Any organization running affected ADC, Gateway, or SD-WAN WANOP firmware is affected, with internet-facing gateways used for remote access at the highest risk. Exploitation is confirmed in the wild: the vulnerability is on CISA's KEV (added 2021-11-03) with known ransomware use, EPSS assigns near-certain (100.0%) probability of exploitation within 30 days, and no public PoC is listed despite confirmed abuse. Do: Upgrade Citrix ADC, Gateway, and SD-WAN WANOP appliances to the fixed firmware builds listed in Citrix advisory CTX267020; if patching cannot be done immediately, apply Citrix's published interim mitigation and restrict internet exposure to the appliance. Because exploitation grants root code execution and persistence, after patching hunt for indicators of compromise (unexpected nsroot account, modified system files, crontab/scheduled entries), kill all active and inactive sessions, and rotate appliance and VPN credentials. Prioritize internet-facing gateways and comply with CISA's required action to apply vendor updates. | 9.8 | 100% | KEV ransomware |
| massroughly 80,000-100,000+ internet-exposed Citrix ADC/Gateway appliances at the time of disclosure, with a far larger total installed base (including… |
Full article425 words · extracted from securityaffairs.com · click to collapse

Australian ACSC published a detailed report on the techniques, tactics, and procedures associated with the threat actor that targeted organizations in the country.
Recently, Australia ‘s prime minister Scott Morrison revealed that a “state-based actor” is targeting government, public services, and businesses.
Warning Australians of “specific risks” and an increased frequency of attacks, the Australian government is working on “specific risks” related to a significant increase in the number of targeted cyber attacks against sensitive institutions and organizations in almost any industry, Morrison told an organised press conference
Morrison highlighted that the attackers have been orchestrated by a sophisticated nation-state actor, but did not attribute it to a specific foreign state. Senior sources told Australia’s ABC News that China-linked APT groups may have been involved in the attacks.
Attackers employed modified proof-of-concept exploit code for known vulnerabilities, experts reported that attackers targets public-facing infrastructure. In many cases, attackers targeted unpatched versions of Telerik user interface (UI) by exploiting CVE-2019-18935, CVE-2017-9248, CVE-2017-11317, CVE-2017-11357 vulnerabilities.
Experts from the Australian Cyber Security Centre (ACSC) discovered that the attacker also exploited a Microsoft SharePoint Remote Code Execution Vulnerability tracked as CVE-2019-0604 and the CVE-2019-19781 vulnerability in Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances.
In other attempts detected by ACSC, threat actors launched spear-phishing to harvest credentials, deliver malware, and steal other sensitive data from the victims.
“The ACSC has identified instances where users have executed malware embedded in email attachments. The text of the email provides the user with a plausible reason to open the attachment. Once opened, the malware will exploit an existing vulnerability or execute directly on the user’s system.” reads the alert issued by the ACSC.
The ACSC pointed out that the attackers did not carry out any disruptive or destructive activities within victim environments.
The threat actors used malware (i.e. Korplug, PlugX) that has been associated with Chinese APT groups, such as OceanLotus, to load a Cobalt Strike payload.
According to the ACSC experts, attackers also use the open-source PowerShell Empire post-exploitation framework.
Once gained a foothold inside the victim network, the attackers attempted to escalated privileges to SYSTEM using common tools, including Juicy Potato and RottenPotatoNG utilities.
The attackers’ arsenal also includes numerous web shells used to maintain access to compromised hosts.
The full report published by ACSC on the techniques, tactics, and procedures associated with the threat actor that targeted organizations in the country is available here.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, ACSC)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/105300/intelligence/acsc-report-chinese-malware.html