JAVS Courtroom Recording Software Backdoored
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-4978 | Embedded Malicious Code (Backdoored ffmpeg) in Justice AV Solutions Viewer Installer The Justice AV Solutions (JAVS) Viewer installer shipped with a trojanized copy of ffmpeg.exe, renamed fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4), classified as CWE-506 embedded malicious code — a supply-chain style compromise rather than a code flaw. The malicious code is triggered when the backdoored fffmpeg.exe binary is run after installing the tampered JAVS Viewer package, at which point it opens a backdoor connection to a malicious command-and-control (C2) server. An attacker gains an outbound channel from the victim machine, enabling potential remote access and follow-on activity such as lateral movement or ransomware staging. Organizations that downloaded and installed the affected JAVS Viewer installer — typically courts and justice agencies using JAVS courtroom audio/video software — are affected. The flaw was added to the CISA Known Exploited Vulnerability catalog on 2024-05-29, indicating known in-the-wild exploitation, and EPSS assigns it a 26.9% probability of exploitation in the next 30 days (98th percentile). Do: Follow the vendor's instructions as required by CISA KEV: uninstall the JAVS Viewer, remove or quarantine any fffmpeg.exe on systems (verify against the published SHA256), and reinstall the Viewer only from a freshly downloaded, verified-clean installer from JAVS. Check endpoint logs for outbound connections to unknown C2 servers and hunt for any fffmpeg.exe processes, and treat any machine where the tampered installer ran as potentially compromised until reviewed. | 8.7 | 27% | KEV PoC |
| nicheunknown, likely on the order of thousands of installations (specialized courtroom AV software) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 8.3.7.250 | e software, tracing it to a binary named "JAVS Viewer Setup 8.3.7.250-1.exe" that was downloaded from the official JAVS site on M |
Full article669 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMay 24, 2024Supply Chain Attack / Malware
Malicious actors have backdoored the installer associated with courtroom video recording software developed by Justice AV Solutions (JAVS) to deliver malware that's associated with a known implant called RustDoor.
The software supply chain attack, tracked as CVE-2024-4978 (CVSS score: 8.7), impacts JAVS Viewer v8.3.7, a component of the JAVS Suite 8 that allows users to create, manage, publish, and view digital recordings of courtroom proceedings, business meetings, and city council sessions.
Cybersecurity firm Rapid7 said it commenced an investigation earlier this month after discovering a malicious executable called "fffmpeg.exe" (note the three Fs) in the Windows installation folder of the software, tracing it to a binary named "JAVS Viewer Setup 8.3.7.250-1.exe" that was downloaded from the official JAVS site on March 5, 2024.
"Analysis of the installer JAVS Viewer Setup 8.3.7.250-1.exe showed that it was signed with an unexpected Authenticode signature and contained the binary fffmpeg.exe," Rapid7 researchers said, adding it "observed encoded PowerShell scripts being executed by the binary fffmpeg.exe."
Both fffmpeg.exe and the installer have been signed by an Authenticode certificate issued to "Vanguard Tech Limited," as opposed to "Justice AV Solutions Inc," the signing entity used to authenticate the legitimate versions of the software.
Upon execution, fffmpeg.exe establishes contact with a command-and-control (C&C) server using Windows sockets and WinHTTP requests in order to send information about the compromised host and await further instructions from the server.
It's also designed to run obfuscated PowerShell scripts that attempt to bypass Antimalware Scan Interface (AMSI) and disable Event Tracing for Windows (ETW), after which it executes a command to download an additional payload that masquerades as an installer for Google Chrome ("chrome_installer.exe") from a remote server.
This binary, in turn, contains code to drop Python scripts and another executable named "main.exe" and launch the latter with the aim of gathering credentials from web browsers. Rapid7's analysis of "main.exe" found software bugs that prevented it from running properly.
RustDoor, a Rust-based backdoor malware, was first documented by Bitdefender earlier this February as targeting Apple macOS devices by mimicking an update for Microsoft Visual Studio as part of likely targeted attacks using job offering lures.
Subsequent analysis by South Korean cybersecurity company S2W unearthed a Windows version codenamed GateDoor that's programmed in Golang.
"Both RustDoor and GateDoor have been confirmed to be distributed under the guise of normal program updates or utilities," S2W researchers Minyeop Choi, Sojun Ryu, Sebin Lee, and HuiSeong Yang noted later that month. "RustDoor and GateDoor have overlapping endpoints used when communicating with the C&C server and have similar functions."
There is infrastructure evidence to connect the malware family to a ransomware-as-a-service (RaaS) affiliate called ShadowSyndicate. However, it has also raised the possibility that they could be acting as a collaborator specializing in providing infrastructure to other actors.
The use of a trojanized JAVS Viewer installer to distribute a Windows version of RustDoor was previously also flagged by S2W on April 2, 2024, in a post shared on X (formerly Twitter). It's currently not clear how the vendor's site was breached and a malicious installer became available for download.
JAVS, in a statement provided to the cybersecurity vendor, said it identified a "potential security issue" with JAVS Viewer version 8.3.7, and that it pulled the impacted version from the website, reset all passwords, and conducted a full audit of its systems.
"No JAVS Source code, certificates, systems, or other software releases were compromised in this incident," the American company said. "The file in question did not originate from JAVS or any third-party associated with JAVS. We highly encourage all users to verify that JAVS has digitally signed any JAVS software they install."
Users are advised to check for indicators of compromise (IoCs), and if found to be infected, completely re-image all affected endpoints, reset credentials, and update to the latest version of JAVS Viewer.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/05/courtroom-software-backdoored-to.html