ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

New Threat Actor “Grayling” Blamed For Espionage Campaign

criticalThreat actorimportance 60CVE-2019-0803

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0803
Local Privilege Escalation in Microsoft Win32k Kernel Component

CVE-2019-0803 is a privilege escalation flaw in Microsoft's Win32k kernel component caused by improper handling of objects in memory. It is triggered locally when code already running on a Windows system reaches the vulnerable Win32k object-handling path, allowing memory corruption that the attacker can leverage. Successful exploitation lets the attacker run arbitrary code in kernel mode, elevating from a low-privileged account to full system-level control. Per the available data, the affected component is Microsoft Win32k across Windows installations, though specific affected Windows versions and builds are not enumerated in the source data and should be confirmed against Microsoft's advisory. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns a 45.2% probability of exploitation within 30 days (99th percentile).

Do: Apply Microsoft Windows security updates per vendor instructions — this flaw was fixed in Microsoft's April 2019 security updates, so ensure systems are running those or later cumulative updates and verify by checking OS build numbers. Prioritize patching endpoints and servers where untrusted or low-privileged users can execute code, given documented ransomware chaining. Treat KEV status as a deadline: systems unpatched for this Win32k flaw should be considered actively targeted.

7.845% KEV ransomware
  • Microsoft Win32k
masshundreds of millions of Windows desktops and servers (Win32k is a core component shipped with essentially all Windows installations)
Full article347 words · extracted from infosecurity-magazine.com · click to collapse

Security researchers have shared evidence of a new APT group that targeted mainly Taiwanese organizations in a cyber-espionage campaign lasting at least four months.

Dubbed “Grayling” by Symantec, the group’s activity began in February 2023 and continued until at least May 2023, stealing sensitive information from manufacturing, IT and biomedical firms in Taiwan, as well as victims in the US, Vietnam and Pacific Islands.

The group deployed DLL sideloading through exported API “SbieDll_Hook” in order to load tools such as a Cobalt Strike Stager, that led to popular post-exploitation tool Cobalt Strike Beacon. It also installed “Havoc” – an open-source, post-exploitation command-and-control (C2) framework used in a similar way to Cobalt Strike.

Grayling used publicly available spyware tool NetSpy, exploited legacy Windows elevation of privileges bug CVE-2019-0803, and downloaded and executed shellcode, the report noted.

Read more on APT activity: Barracuda Zero-Day Exploited by Chinese Actor

“Other post-exploitation activity performed by these attackers includes using kill processes to kill all processes listed in a file called processlist.txt, and downloading the publicly available credential-dumping tool Mimikatz,” explained Symantec.

“While we do not see data being exfiltrated from victim machines, the activity we do see and the tools deployed point to the motivation behind this activity being intelligence gathering.”

The security vendor said that Grayling’s modus operandi was fairly typical of APT groups today, in blending custom and publicly available tools; the latter to help it stay under the radar. Havoc and Cobalt Strike are particularly useful, and popular, in featuring a wide range of post-exploitation capabilities.

“It is often easier for even skilled attackers to use existing tools like this than to develop custom tools of their own with similar capabilities,” Symantec continued.

“The use of publicly available tools can also make attribution of activity more difficult for investigators. The steps taken by the attackers, such as killing processes etc., also indicate that keeping this activity hidden was a priority for them.”

Although the vendor stopped short of naming a potential nation state, it’s clear that the targets sought out by Grayling align with Beijing’s geopolitical interests.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/threat-actor-grayling-espionage/