ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

RIG Exploit Kit Now Infects Victims' PCs With Dridex Instead of Raccoon Stealer

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-8174
Out-of-Bounds Write RCE in Microsoft Windows VBScript Engine

CVE-2018-8174 is an out-of-bounds write (CWE-787) in the Microsoft Windows VBScript engine, caused by the way it handles objects in memory. An attacker triggers it by convincing a user to visit a specially crafted website or open crafted content that invokes the VBScript engine (for example via Internet Explorer or a document preview), requiring user interaction. Successful exploitation yields remote code execution with the privileges of the logged-on user, enabling program installation, data theft and account takeover. All listed Windows client and server releases are affected: Windows 7, 8.1, RT 8.1, Windows 10 (1607-1803), and Windows Server 2008/2008 R2, 2012/2012 R2, 2016. Exploitation is in the wild: the flaw was fixed in the May 2018 Patch Tuesday, is listed in CISA KEV with known ransomware use, and public PoCs (0patch, ExploitDB 44741) and exploit kit usage have been documented; EPSS puts its 30-day exploitation probability at 88.5%.

Do: Apply Microsoft's May 2018 security updates (and any later cumulative or Extended Security Updates) to every listed Windows client and server release, as required by the CISA KEV listing, prioritizing internet-reachable and user-facing systems given known ransomware use. Upgrade out-of-support platforms (Windows 7/8.1/RT 8.1, Server 2008/2008 R2, 2012/2012 R2) to supported builds or ensure ESU coverage. As interim mitigation, block VBScript execution in Internet Explorer web zones using Microsoft's documented Group Policy/registry settings, and hunt for prior exploitation on legacy systems.

7.588% KEV ransomware PoC ×2
  • microsoft windows 10 1607, 1703, 1709, 1803 (pre-May 2018 security updates)
  • microsoft windows 7 all supported builds prior to the May 2018 security update
  • microsoft windows 8.1 all supported builds prior to the May 2018 security update
  • +4 more
masshundreds of millions of Windows PCs and servers (affected desktop releases dominated the ~1B+ device Windows install base at disclosure)
CVE-2019-0752
Type Confusion RCE in Microsoft Internet Explorer Scripting Engine

CVE-2019-0752 is a type confusion (CWE-843) memory corruption vulnerability in the way the scripting engine used by Internet Explorer handles objects in memory, and it is distinct from the related scripting-engine flaws CVE-2019-0739, CVE-2019-0753, and CVE-2019-0862. An attacker triggers it by convincing a user to view attacker-controlled or attacker-crafted web content in Internet Explorer, where malformed handling of in-memory objects corrupts memory (the CVSS vector reflects a network attack requiring user interaction with high attack complexity). Successful exploitation yields remote code execution with the privileges of the current user, giving the attacker high confidentiality, integrity, and availability impact on the host. Anyone running Internet Explorer on supported Windows client or server systems is exposed; the provided data does not specify exact affected version ranges, though the public proof-of-concept was demonstrated on Windows 10 1809 (build 17763.316). Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15) with known ransomware use, carries a top-percentile EPSS score of 81.6%, and contemporary reporting ties scripting-engine flaws like this to exploit kits (e.g., RIG) delivering malware such as Dridex.

Do: Apply Microsoft's security updates that address CVE-2019-0752 via Windows Update or WSUS, per the CISA KEV required action, and audit legacy Windows clients and servers for any that have not been patched. Where updates are impractical (e.g., out-of-support systems), stop using Internet Explorer as the default browser, restrict or disable scripting in the Internet zone, and consider blocking IE-facing access to untrusted sites. Because exploit kits (e.g., RIG) and ransomware operators have leveraged IE scripting-engine flaws, prioritize patching user workstations and shared/multi-user systems.

7.582% KEV ransomware PoC
  • microsoft internet explorer
masshundreds of millions of Windows devices/users with Internet Explorer present
CVE-2021-26411
Use-After-Free Memory Corruption in Microsoft Internet Explorer Exploited in the Wild

CVE-2021-26411 is a use-after-free (CWE-416) memory corruption vulnerability in Microsoft Internet Explorer's web rendering engine that can lead to remote code execution. It is triggered when a user, typically lured via a link, email, or watering-hole page, views attacker-controlled web content that corrupts memory, consistent with the CVSS profile requiring network access and user interaction. A successful attacker gains code execution in the context of the logged-on user, which in observed campaigns was chained into malware delivery (including exploit-kit payloads such as Dridex and VBA-based malware). Any Windows system that renders web content with Internet Explorer or its IE/MSHTML components (Edge is also listed among affected CPE products) is potentially affected, though specific version ranges are not provided in the source data. The flaw was exploited as a zero-day around Microsoft's March 2021 Patch Tuesday, was added to CISA KEV on 2021-11-03 with known ransomware use, and carries an 80.8% EPSS probability of exploitation within 30 days.

Do: Apply Microsoft's March 2021 cumulative security updates for Internet Explorer, or any later cumulative update, across all Windows clients and servers, prioritizing user workstations per the CISA KEV required action. Review proxy and endpoint logs for visits to compromised watering-hole sites (notably Korean-language news sites) and for follow-on malware such as Dridex, and restrict or disable IE/legacy IE-mode rendering of untrusted web content where feasible.

8.881% KEV ransomware
  • microsoft internet_explorer
  • microsoft edge
mass≈hundreds of millions of Windows endpoints (IE/MSHTML components are present on effectively all supported Windows clients and servers)
Full article344 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 22, 2022

The operators behind the Rig Exploit Kit have swapped the Raccoon Stealer malware for the Dridex financial trojan as part of an ongoing campaign that commenced in January 2022.

The switch in modus operandi, spotted by Romanian company Bitdefender, comes in the wake of Raccoon Stealer temporarily closing the project after one of its team members responsible for critical operations passed away in the Russo-Ukrainian war in March 2022.

The Rig Exploit Kit is notable for its abuse of browser exploits to distribute an array of malware. First spotted in 2019, Raccoon Stealer is a credential-stealing trojan that's advertised and sold on underground forums as a malware-as-a-service (MaaS) for $200 a month.

That said, the Raccoon Stealer actors are already working on a second version that's expected to be "rewritten from scratch and optimized." But the void left by the malware's exit is being filled by other information stealers such as RedLine Stealer and Vidar.

Dridex (aka Bugat and Cridex), for its part, has the capability to download additional payloads, infiltrate browsers to steal customer login information entered on banking websites, capture screenshots, and log keystrokes, among others, through different modules that allow its functionality to be extended at will.

In April 2022, Bitdefender discovered another Rig Exploit Kit campaign distributing the RedLine Stealer trojan by exploiting an Internet Explorer flaw patched by Microsoft last year (CVE-2021-26411).

That's not all. Last May, a separate campaign exploited two scripting engine vulnerabilities in unpatched Internet Explorer browsers (CVE-2019-0752 and CVE-2018-8174) to deliver a malware called WastedLoader, so named for its similarities to WasterLocker but lacking the ransomware component.

"This once again demonstrates that threat actors are agile and quick to adapt to change," the cybersecurity firm said. "By design, Rig Exploit Kit allows for rapid substitution of payloads in case of detection or compromise, which helps cyber criminal groups recover from disruption or environmental changes."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/06/rig-exploit-kit-now-infects-victims-pcs.html