ZeroHour
Security Affairspublished ()ingested @securityaffairs

North Korea-linked APT37 exploited IE zero

criticalThreat actor exploited in the wildimportance 60CVE-2024-38178CVE-2022-41128

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-41128
Out-of-bounds Write RCE in Microsoft Windows JScript9 Scripting Engine

CVE-2022-41128 is a remote code execution flaw in the JScript9 scripting language on Microsoft Windows, classed by the CWE taxonomy as an out-of-bounds write (CWE-787), meaning crafted input can write past the end of an allocated memory buffer. Microsoft's description is limited, but flaws of this type in scripting engines are typically triggered when the engine processes attacker-crafted script content, such as script embedded in a web page or document. Successful exploitation would let an attacker execute arbitrary code in the context of the affected process on the target Windows system. Any Windows deployment that processes content through the JScript9 engine is affected, which spans a broad share of the Windows installed base. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-11-08, indicating confirmed in-the-wild exploitation; no public proof-of-concept is known, EPSS puts the 30-day exploitation probability at 24.6% (98th percentile), and ransomware use is unknown.

Do: Apply Microsoft's Windows security updates per vendor instructions without delay, prioritizing internet-facing and user-workstation systems because the flaw is KEV-listed as actively exploited. Until patched, limit exposure to untrusted script-bearing web content and documents from unverified sources, and verify remediation status against Microsoft's update guidance.

8.825% KEV
  • Microsoft Windows
mass≈1 billion+ Windows devices (order of magnitude; the engine ships with Windows itself)
CVE-2024-38178
Unauthenticated RCE via Memory Corruption in Microsoft Windows Scripting Engine

CVE-2024-38178 is a memory corruption flaw (CWE-843 type confusion) in the Microsoft Windows Scripting Engine that allows an unauthenticated attacker to execute arbitrary code. Exploitation is triggered when a user is lured into opening a specially crafted URL, so no prior authentication or network access to the target is required. A successful attack gains remote code execution, typically in the context of the fooled user's privileges. Any supported Microsoft Windows system with the scripting engine is affected, per CISA's listing of 'Microsoft Windows'. The vulnerability is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2024-08-13, coinciding with Microsoft's August 2024 Patch Tuesday, and EPSS assigns a high 41.4% probability of exploitation in the next 30 days.

Do: Apply Microsoft's August 2024 Windows cumulative security updates immediately, prioritizing internet-facing and high-value systems, and verify patch levels against the KBs released 2024-08-13. As interim mitigation, limit user exposure to untrusted links and consider restricting or disabling legacy scripting/IE-mode rendering where business needs allow. No public PoC is known, but KEV listing confirms active exploitation, so hunt for anomalous process spawns from browsing/link-opening activity and apply CISA's required action of vendor mitigations or discontinuing use.

7.541% KEV
  • Microsoft Windows (Scripting Engine) CISA lists 'Microsoft Windows' without enumerating ranges; affected Windows releases are those covered by Microsoft's August 2024 security updates
masshundreds of millions of Windows devices worldwide
Full article707 words · extracted from securityaffairs.com · click to collapse

North Korea-linked group APT37 exploited an Internet Explorer zero-day vulnerability in a supply chain attack.

A North Korea-linked threat actor, tracked as APT37 (also known as RedEyes, TA-RedAnt, Reaper, ScarCruft, Group123), exploited a recent Internet Explorer zero-day vulnerability, tracked as CVE-2024-38178 (CVSS score 7.5), in a supply chain attack.

Threat intelligence firm AhnLab and South Korea’s National Cyber Security Center (NCSC) linked the attack to the North Korean APT.

The vulnerability is a scripting engine memory corruption issue that could lead to arbitrary code execution.

“This attack requires an authenticated client to click a link in order for an unauthenticated attacker to initiate remote code execution.” reads the advisory published by Microsoft, which addressed the flaw in August. “Successful exploitation of this vulnerability requires an attacker to first prepare the target so that it uses Edge in Internet Explorer Mode.”

APT37 compromised the online advertising agency behind the Toast ad program to carry out a supply chain attack.

The attackers exploited the zero-day Internet Explorer vulnerability in the toast ad program, which used an outdated IE-based WebView for initial access in a supply chain attack.

The researchers pointed out that despite IE’s end of support in June 2022, the vulnerability still impacted certain Windows applications.

The threat actors compromised a Korean online ad agency server, injecting vulnerability code into ad content scripts. This led to a zero-click attack, requiring no user interaction, as the ad program automatically downloaded and rendered the malicious content.

“This operation exploited a zero-day vulnerability in IE to utilize a specific toast ad program that is installed alongside various free software. [Toast is] A type of popup notification that appears at the bottom (usually right bottom) of the desktop screen.” reads the advisory published by AhnLab.

“Many toast ad programs use a feature called WebView to render web content for displaying ads. However, WebView operates based on a browser. Therefore, if the program creator used IE-based WebView to write the code, IE vulnerabilities could also be exploited in the program. As a result, TA-RedAnt exploited the toast ad program that were using the vulnerable IE browser engine (jscript9.dll), which is no longer supported, as an initial access vector. Microsoft ended its support for IE in June 2022. However, attacks that target some Windows applications that still use IE are continuously being discovered, so organizations and users need to be extra cautious and update their systems with the latest security patches.”

The root cause of the vulnerability is the erroneous treatment of a type of data during the optimization process of IE’s JavaScript engine (jscript9.dll), allowing type confusion to occur. APT37 exploited this flaw to trick victims into downloading malware on their desktops with the toast ad program installed. Once the systems are infected, attackers can perform multiple malicious activities such as executing remote commands.

The report published by AhnLab includes details on the attack and indicators of compromise (IoCs).

APT37 has been active since at least 2012, it made the headlines in early February 2028, when researchers revealed that the APT group leveraged a zero-day vulnerability in Adobe Flash Player to deliver malware to South Korean users.

Cyber attacks conducted by the APT37 group mainly targeted government, defense, military, and media organizations in South Korea.

In December 2022, the APT37 group actively exploited another Internet Explorer zero-day vulnerability, tracked as CVE-2022-41128, in attacks aimed at South Korean users. Google Threat Analysis Group researchers discovered the zero-day vulnerability in late October 2022, it was exploited by APT37 using specially crafted documents.

In February 2018, FireEye linked the APT37 group to the North Korean government based on the following clues:

  • the use of a North Korean IP;
  • malware compilation timestamps consistent with a developer operating in the North Korea time
    zone (UTC +8:30) and follows what is believed to be a typical North Korean workday;
  • objectives that align with Pyongyang’s interests(i.e. organizations and individuals involved in Korean
    Peninsula reunification efforts);

Researchers from FireEye revealed that the nation-state actor also targeted entities in Japan, Vietnam, and even the Middle East in 2017. The hackers targeted organizations in the chemicals, manufacturing, electronics, aerospace, healthcare, and automotive sectors.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, APT)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/169983/apt/north-korea-apt37-ie-zero-day.html