ZeroHour
Security Affairspublished ()ingested @securityaffairs

China-linked TA413 targets Tibetan entities with new backdoor

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-1040
Authentication Bypass Leading to Unauthenticated RCE in Sophos Firewall (SFOS)

CVE-2022-1040 is a critical authentication bypass in the User Portal and Webadmin of Sophos Firewall (SFOS) version v18.5 MR3 and older. A remote, unauthenticated attacker who can reach either web-facing service bypasses authentication and executes code on the firewall appliance. Successful exploitation yields full device compromise (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling traffic interception, persistence, and pivoting into the protected network. Any organization running an affected Sophos Firewall version where the User Portal or Webadmin is reachable, especially from the internet, is exposed. Exploitation is confirmed in the wild: it was exploited as a zero-day in March 2022, added to CISA's Known Exploited Vulnerabilities Catalog on 2022-03-31, and used in campaigns attributed to Chinese actors, including a U.S. indictment of a Chinese hacker for exploiting the flaw.

Do: Upgrade Sophos Firewall to a fixed release (v18.5 MR4 or later, per Sophos' patch instructions). Until patched, restrict access to the User Portal and Webadmin to trusted management networks or VPN clients and remove any direct internet exposure to these services. Review device and authentication logs for signs of exploitation, including unexpected or modified administrator accounts and configuration changes, and follow the vendor/CISA required action to apply updates.

9.8100% KEV PoC ×2
  • Sophos Firewall (SFOS) v18.5 MR3 and older
largetens of thousands of internet-exposed User Portal/Webadmin instances among hundreds of thousands of deployed Sophos Firewall appliances
CVE-2022-30190
MSDT URL Protocol Remote Code Execution in Microsoft Windows (Follina)

CVE-2022-30190 (Follina) is a remote code execution flaw in the Microsoft Windows Support Diagnostic Tool (MSDT) when MSDT is invoked through its ms-msdt URL protocol by a calling application such as Microsoft Word. Attackers trigger it by luring a user into opening a malicious document — typically a Word/RTF file whose link or remotely linked template launches the ms-msdt: URI with attacker-supplied commands — and CVSS 3.1 rates it 7.8 with a local attack vector and required user interaction. A successful exploit runs arbitrary code with the privileges of the calling application, allowing the attacker to install programs, view, change or delete data, or create new accounts in the user's context. Per the CISA data, affected platforms are Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 and 2012 — essentially any Windows installation that ships MSDT, with Office/Word as the common delivery vector. Exploitation is confirmed in the wild: Microsoft acknowledged it as an exploited zero-day, CISA added it to the KEV on 2022-06-14 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.2% (99th percentile), and contemporaneous reporting also tied its use to espionage actors including APT28.

Do: Apply Microsoft's security updates per vendor instructions (the fix shipped in the June 2022 Patch Tuesday releases for the affected Windows versions), as required by CISA's KEV. If patching must be delayed, follow Microsoft's documented mitigation to disable the MSDT URL protocol (remove or restrict the HKEY_CLASSES_ROOT\ms-msdt registry key) and enforce Office Protected View / block Word from fetching remote templates over the network. Hunt for exploitation by checking whether Office processes (WINWORD.exe) launch msdt.exe or sdiagnhost.exe, or whether ms-msdt: URIs are invoked unexpectedly.

7.899% KEV ransomware PoC
  • Microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows 7
  • +4 more
mass≈1 billion+ Windows devices (effectively the entire supported Windows installed base)

Indicators of compromiseAll →

TypeIndicatorContext
domaingmail.comyears (such as tseringkanyaq@yahoo[.]com and mediabureauin@gmail[.]com), a circumstance that allowed the researchers to connecti
domainyahoo.comer addresses for up to several years (such as tseringkanyaq@yahoo[.]com and mediabureauin@gmail[.]com), a circumstance that allow
Full article508 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 26, 2022

China-linked cyberespionage group TA413 exploits employ a never-before-undetected backdoor called LOWZERO in attacks aimed at Tibetan entities.

A China-linked cyberespionage group, tracked as TA413 (aka LuckyCat), is exploiting recently disclosed flaws in Sophos Firewall (CVE-2022-1040) and Microsoft Office (CVE-2022-30190) to deploy a never-before-detected backdoor called LOWZERO in attacks aimed at Tibetan entities.

The TA413 APT group is known to be focused on Tibetan organizations across the world, in past attacks threat actors used a malicious Firefox add-on, dubbed FriarFox, to steal Gmail and Firefox browser data and deliver malware on infected systems.

In June, the TA413 group has been observed exploiting the Follina zero-day flaw (tracked as CVE-2022-30190 and rated CVSS score 7.8) in Microsoft Office in attacks in the wild.

“Over the first half of 2022, we have observed TA413 exploit a now-patched zero-day vulnerability targeting the Sophos Firewall product (CVE-2022-1040), weaponize the “Follina” (CVE-2022-30190) vulnerability shortly after discovery and publication, and employ a newly observed custom backdoor we track as LOWZERO in campaigns targeting Tibetan entities.” reads a report published by Recorded Future. “This willingness to rapidly incorporate new techniques and methods of initial access contrasts with the group’s continued use of well known and reported capabilities, such as the Royal Road RTF weaponizer, and often lax infrastructure procurement tendencies.” TA413 has been targeting Tibetans entities since at least 2020, the group employs multiple malware, including ExileRAT, Sepulcher, and a custom malicious Mozilla Firefox browser extension tracked as FriarFox.

The attackers use Royal Road RTF builder to create weaponized documents that exploits the above flaws to deliver LOWZERO malware.

Experts noticed that the threat actors have regularly reused phishing email sender addresses for up to several years (such as tseringkanyaq@yahoo[.]com and mediabureauin@gmail[.]com), a circumstance that allowed the researchers to connection multiple campaign to the group’s activity. 

In May 2022, the experts uncovered a spear-phishing campaign targeting a Tibetan organization containing a link to a Royal Road sample hosted on the Google Firebase service. The RTF document was crafted to exploit the Follina vulnerability to execute a PowerShell command and download the backdoor from a remote server.

Also put to use in a spear-phishing attack identified in May 2022 is a malicious RTF document that exploited flaws in Microsoft Equation Editor to drop the custom LOWZERO implant. This is achieved by employing a Royal Road RTF weaponizer tool, which is widely shared among Chinese threat actors.

The LOWZERO backdoor has a modular structure, it downloads specific modules from the C2 if the compromised machine is of interest to the threat actor.

“The group continues to incorporate new capabilities while also relying on tried-and-tested TTPs. ” concludes the report. “More widely, TA413’s adoption of both zero-day and recently published vulnerabilities is indicative of wider trends with Chinese cyber-espionage groups whereby exploits regularly appear in use by multiple distinct Chinese activity groups prior to their widespread public availability.”

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, APT)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/136252/apt/ta413-targets-tibet-backdoor.html