ZeroHour
The Recordpublished ()ingested

Local governments allegedly targeted with Iranian ‘Drokbk’ malware through Log4j vulnerability

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-44228
JNDI Injection Remote Code Execution in Apache Log4j2 (Log4Shell)

Apache Log4j2, an extremely widely used Java logging library, fails to protect its JNDI lookup feature against attacker-controlled JNDI-related endpoints (CWE-20, CWE-502), so crafted text processed by the logger causes the Java runtime to fetch and load attacker-supplied objects, leading to remote code execution. The flaw is triggered whenever attacker-controlled input reaches the logging API and is parsed for JNDI lookups, a pattern common in web servers and enterprise Java applications that log user-supplied fields such as headers or form values. Successful exploitation yields arbitrary code execution under the privileges of the affected application, giving attackers a foothold for lateral movement, data theft, and ransomware deployment. Any Java application or product that ships or bundles an affected Apache Log4j2 release is exposed, making this one of the most broadly deployed vulnerabilities ever disclosed. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-12-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days.

Do: Inventory all Java applications and dependencies for Apache Log4j2 and apply the vendor's patched updates, or remove affected assets from the network, as required by CISA's KEV catalog. Where updates are not yet available, use the temporary mitigations in CISA's ED-22-02 recommended-mitigation guidance, such as disabling message lookups, only until patches are applied. Prioritize internet-facing and business-critical systems and hunt for exploitation activity given known ransomware use.

10.0100% KEV ransomware PoC ×9
  • Apache Log4j2
masshundreds of millions of Java applications/devices, with hundreds of thousands of internet-exposed services
CVE-2021-45046
Remote Code Execution in Apache Log4j2 via Incomplete Log4Shell Fix

CVE-2021-45046 is a remote code execution and information disclosure flaw in Apache Log4j2 (CWE-917) that resulted from an incomplete fix to CVE-2021-44228 (Log4Shell), leaving the Thread Context Lookup Pattern vulnerable in certain non-default configurations. It is triggered when an application logs attacker-controlled data using layouts or patterns that perform Thread Context (MDC) lookups, allowing crafted lookup expressions to be evaluated against untrusted input. A successful attacker can achieve remote code execution, or potentially information disclosure, on the affected service. Any deployment of Apache Log4j2 that relies on the affected non-default lookup configurations is exposed, which given Log4j2's ubiquity in Java applications and embedded products means a very large installed base. Exploitation is confirmed: the flaw is in CISA KEV (added 2023-05-01) with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days.

Do: Upgrade Log4j2 to 2.17.0 or later per vendor instructions (or 2.12.3/2.3.1 for the legacy 2.12/2.3 branches), since the 2.16.0 fix was itself incomplete in some non-default configurations. Where upgrading is not immediately possible, remove the JndiLookup class from the Log4j2 jar or disable lookup processing, and audit applications and dependencies that bundle Log4j2 while following the CISA KEV required action to apply vendor updates.

9.0100% KEV ransomware
  • Apache Log4j2 Log4j 2.x; per Apache advisory, 2.0-beta9 through 2.15.0 (and 2.16.0 in some non-default configurations), fixed in 2.17.0 and in 2.12.3/2.3.1 for older branches
massmillions of Java deployments worldwide, with hundreds of thousands of internet-exposed services observed in public scans during the Log4Shell campaign
Full article599 words · extracted from therecord.media · click to collapse

The networks of several local governments in the U.S. have been targeted with the Drokbk malware, allegedly wielded by Iranian government-backed groups exploiting the Log4j vulnerability.

Researchers with Secureworks Counter Threat Unit said on Friday that Iranian threat group Cobalt Mirage – which other researchers call Nemesis Kitten or UNC2448 – has been actively looking to exploit U.S. networks in a campaign that began in February. 

The group uses the Drokbk malware to maintain their access in a victim’s network, according to Rafe Pilling, principal security researcher for Secureworks.

Secureworks noted that about a month ago, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory about an Iranian advanced persistent threat (APT) group that accessed the server of a federal agency by exploiting the Log4j vulnerability.

Secureworks said that even though CISA did not name the group at the time, they believe the same actors were also targeting local governments in the U.S., as well as organizations in the finance and education industries. 

“However, target selection by Cobalt Mirage is likely opportunistic driven by presence of vulnerabilities that the group are using. i.e. Log4j vulnerabilities in VMware Horizon (CVE-2021-44228),” the researchers said. 

One thing that stood out to the researchers is the fact that the Drokbk malware uses a technique considered unusual for Iranian malware involving GitHub to obtain its command and control infrastructure.

Secureworks researchers first found evidence of Drokbk malware in February and said it is typically used after the group has already infiltrated a network.

“The February intrusion that Secureworks incident responders investigated began with a compromise of a VMware Horizon server using two Log4j vulnerabilities (CVE-2021-44228 and CVE-2021-45046),” they said. 

“Forensic artifacts indicated Drokbk.exe was extracted from a compressed archive (Drokbk.zip) hosted on the legitimate transfer.sh online service. This code identifies the specific GitHub account and the request used to locate the malware's C2 server [command and control]. In this campaign, the threat actor used a GitHub account with the username Shinault23.”

The researchers noted that this tactic gives the group resiliency against the shutting down of its GitHub accounts because, in that instance, they can simply create a new account with a matching repository name.

The report comes one day after cybersecurity firm Deep Instinct released its own report about a long-running campaign by MuddyWater – a cyber espionage group they believe works within Iran's Ministry of Intelligence and Security. 

The firm uncovered a campaign running since at least 2017 where the group targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.

The report focuses on a recent spearphishing campaign targeting Armenia, Azerbaijan, Egypt, Iraq, Israel, Jordan, Oman, Qatar, Tajikistan and the United Arab Emirates.

The spearphishing emails began at the end of 2021 and continued through this fall. 

In September, CISA worked with cyber agencies at several allied nations to release a technical advisory about the tactics used by the hackers in a number of incidents, noting that they have observed these APT actors exploiting VMware Horizon Log4j vulnerabilities for initial access. 

“The IRGC-affiliated actors have used this access for follow-on activity, including disk encryption and data extortion, to support ransom operations,” CISA said. 

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/local-governments-allegedly-targeted-with-iranian-drokbk-malware-through-log4j-vulnerability