Alarming Surge in TrueBot Activity Revealed with New Delivery Vectors
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-31199 | Unauthenticated Deserialization RCE in Netwrix Auditor Video Recording Component CVE-2022-31199 is an insecure object deserialization flaw (CWE-502; CISA also tags CWE-122) in the User Activity Video Recording component of Netwrix Auditor. An unauthenticated remote attacker who can reach the component's TCP port 9004 can trigger the flaw; this port is commonly blocked by standard enterprise firewalling, which limits how many environments are directly reachable. Successful exploitation yields arbitrary code execution running as NT AUTHORITY\SYSTEM, giving the attacker full local privileges on the affected host and a strong foothold for follow-on activity such as ransomware. Any organization running Netwrix Auditor with the User Activity Video Recording component deployed is affected, with the available data providing no specific affected version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11 with known ransomware use, and EPSS assigns a 36% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. Do: Apply updates per vendor instructions immediately, or discontinue use of the affected component if updates are unavailable, per CISA's required action. Inventory whether the User Activity Video Recording component is installed and whether TCP port 9004 is reachable from user networks, VPNs, or the internet, and restrict that port to trusted hosts as a stopgap. Prioritize remediation given the KEV listing and known ransomware use. | 9.8 | 36% | KEV ransomware PoC |
| large≈10,000–100,000 installations (estimated) |
Full article326 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 05, 2023Malware / Cyber Threat
A surge in TrueBot activity was observed in May 2023, cybersecurity researchers disclosed.
"TrueBot is a downloader trojan botnet that uses command and control servers to collect information on compromised systems and uses that compromised system as a launching point for further attacks," VMware's Fae Carlisle said.
Active since at least 2017, TrueBot is linked to a group known as Silence that's believed to share overlaps with the notorious Russian cybercrime actor known as Evil Corp.
Recent TrueBot infections have leveraged a critical flaw in Netwrix Auditor (CVE-2022-31199, CVSS score: 9.8) as well as Raspberry Robin as delivery vectors.
The attack chain documented by VMware, on the other hand, starts off with a drive-by-download of an executable named "update.exe" from Google Chrome, suggesting that users are lured into downloading the malware under the pretext of a software update.
Once run, update.exe establishes connections with a known TrueBot IP address located in Russia to retrieve a second-stage executable ("3ujwy2rz7v.exe") that's subsequently launched using Windows Command Prompt.
The executable, for its part, connects to a command-and-control (C2) domain and exfiltrates sensitive information from the host. It's also capable of process and system enumeration.
"TrueBot can be a particularly nasty infection for any network," Carlisle said. "When an organization is infected with this malware, it can quickly escalate to become a bigger infection, similar to how ransomware spreads throughout a network."
The findings come as SonicWall detailed a new variant of another downloader malware known as GuLoader (aka CloudEyE) that's used to deliver a wide range of malware such as Agent Tesla, Azorult, and Remcos.
"In the latest variant of GuLoader, it introduces new ways to raise exceptions that hamper complete analysis process and its execution under controlled environment," SonicWall said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/06/alarming-surge-in-truebot-activity.html