ZeroHour
CyberScooppublished ()ingested @gregotto

Multi-national warning issued over Russia’s targeting of logistics, tech firms

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-23397CVE-2023-38831

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-23397
Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak)

CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates.

Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook.

9.897% KEV
  • Microsoft 365 Apps Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Long Term Servicing Channel (LTSC) Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • +1 more
masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite)
CVE-2023-38831
Code Execution in RARLAB WinRAR via Crafted ZIP File/Folder Name Confusion

RARLAB WinRAR before 6.23 mishandles ZIP archives that contain a benign file (such as a JPG) alongside a folder with the same name, causing the folder's contents - which can include malicious executable files - to be processed when the user merely attempts to view the benign file. By sending a crafted ZIP archive, an attacker gains arbitrary code execution on the victim's machine with the user's privileges. Because the flaw is local (AV:L) and requires user interaction, risk is limited to Windows systems running an unpatched copy of WinRAR, while machines without the tool are unaffected. The bug was actively exploited in the wild from April through October 2023, including by government-backed actors (APT28), SideCopy attacks on Indian government entities, ransomware operations, and trading-account theft campaigns, and it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-08-24.

Do: Upgrade all Windows systems running WinRAR to version 6.23 or later, which fixes this flaw; if patching is not immediately possible, treat ZIP files from untrusted sources with caution and check archives for duplicate file/folder names before opening. Given KEV listing with known ransomware use and public proof-of-concept exploits, hunt for compromise by reviewing whether unexpected executables or scripts ran when ZIP archives were opened, and apply vendor mitigations per CISA's required action or discontinue use if mitigations are unavailable.

7.898% KEV ransomware PoC ×4
  • RARLAB WinRAR before 6.23
masshundreds of millions of users/installations worldwide (WinRAR is one of the most widely installed Windows archive utilities)
Full article939 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The campaign traces back at least to early 2022, coinciding with the start of Russia’s full-scale invasion of Ukraine.

Listen to this article

0:00

Learn more.

The Russian flag flies at the embassy's compound in Washington, DC, on April 15, 2021. (Photo by MANDEL NGAN/AFP via Getty Images)

A joint advisory from intelligence and cybersecurity agencies in the United States, United Kingdom, Canada, Australia and multiple European countries has detailed an ongoing Russian state-sponsored campaign targeting Western logistics organizations and technology companies, especially those supporting aid to Ukraine. The campaign, orchestrated by the group known as APT28 or Fancy Bear, has relied heavily on established techniques to breach organizations and extract sensitive data.

The campaign traces back at least to early 2022, coinciding with the start of Russia’s full-scale invasion of Ukraine. The group, which is tied to Russia’s Main Intelligence Directorate (GRU),  has focused on logistics organizations and IT firms involved in coordinating, transporting, and delivering foreign assistance to Ukraine. 

Entities across nearly all modes of transportation — including air, rail, and sea — as well as government, defense, and IT service sectors have been singled out. Targets are widespread, spanning the United States, Ukraine, several NATO member states, and bordering countries such as Bulgaria, France, Germany, Poland, Romania, and Slovakia.

Those running the campaign have deployed a mixture of previously observed tactics, techniques, and procedures. These have included:

  • Credential guessing and brute-force attacks supported by anonymization networks such as Tor and commercial VPNs.
  • Spearphishing attempts aimed at harvesting credentials or delivering malware, with lures typically dressed as official or professional documents and customized to recipients’ languages.
  • Exploitation of known software vulnerabilities, including the Outlook NTLM flaw (CVE-2023-23397), multiple Roundcube webmail vulnerabilities, and a widely publicized WinRAR bug (CVE-2023-38831).
  •  Abuse and compromise of internet-facing infrastructure, such as corporate VPNs and small office/home office (SOHO) devices, to mask malicious activity and proximate operations closer to intended victims.
  • Efforts aimed at industrial control system manufacturers, particularly in railway management, though the extent of success in these cases remains unconfirmed.

Once inside a network, actors conduct reconnaissance to identify further targets and sensitive personnel, leveraging tools like Impacket and PsExec for lateral movement. They have been observed deploying malware variants — most notably HeadLace and Masepie — and using techniques such as scheduled tasks, registry modifications, and malicious shortcuts to stay inside a network.

The campaign incorporates multi-stage phishing infrastructure, with redirectors screening connection attempts by location or browser details, adding another layer of security that makes their campaigns harder to detect. 

Beyond traditional IT environments, the campaign has expanded to include widespread targeting of IP cameras, especially those at border crossings and transport hubs. Using both default and brute-forced credentials, the group has obtained access to the video feeds and metadata of thousands of cameras, the majority located in Ukraine and neighboring states. The intent appears to be to physically track aid deliveries and transport activity.

The campaign showcases the group’s continued reliance on public vulnerabilities and “living-off-the-land” (LOTL) approaches. The advisory notes that tools and utilities commonly used for system administration, such as ntdsutil, wevtutil, and PowerShell, are regularly repurposed by attackers. As a result, organizations are cautioned to develop nuanced detection strategies to avoid false positives.

The advisory, issued by 25 intelligence, military, and cybersecurity agencies, reflects an unprecedented level of international collaboration and information sharing on Russian state cyber operations. While the technical means and targets have become more complex and widespread, the campaign’s objectives remain overtly aligned with Russia’s military and strategic interests concerning Ukraine and the wider region.

Private companies have also been observing Russian actions taken in relation to its war with Ukraine. The GRU has also been targeting email accounts of top Ukrainian officials and executives at foreign defense contractors supplying weapons to Ukraine, according to ESET research. Since at least 2023, the group has used spearphishing and exploited cross-site scripting vulnerabilities in webmail platforms like Roundcube, Horde, MDaemon, and Zimbra.

“Russian military intelligence has an obvious need to track the flow of material into Ukraine, and anyone involved in that process should consider themselves targeted,” said John Hultquist, chief analyst, Google Threat Intelligence Group. “Beyond the interest in identifying support to the battlefield, there is an interest in disrupting that support through either physical or cyber means. These incidents could be precursors to other serious actions.”

You can read the full advisory here

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/russian-apt28-cyberattacks-target-western-logistics-ukraine/