ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

FreakOut! Ongoing Botnet Attack Exploiting Recent Linux Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-28188
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

NVD description · AI analysis pending
9.897% PoC ×2
  • terra-master tos
CVE-2020-7961
Deserialization RCE in Liferay Portal via JSON Web Services

Liferay Portal contains a deserialization of untrusted data flaw (CWE-502) that allows remote attackers to execute arbitrary code through the product's JSON web services. An attacker triggers it by sending crafted, untrusted serialized data to the portal's JSON web services endpoints; the available data does not specify an affected version range or authentication requirements. Successful exploitation yields remote code execution on the portal server, a foothold attackers can use to pivot into the wider environment. Any organization running Liferay Portal is affected, with internet-facing deployments at highest risk; public internet-wide scans have counted tens of thousands of exposed instances. The vulnerability is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with a 99.9% EPSS (100th percentile), indicating active or near-certain exploitation, though no public PoC is documented, ransomware use is unknown, and CVSS has not been scored.

Do: Apply Liferay's updates per vendor instructions as required by CISA KEV, prioritizing internet-facing portals, and use the Liferay advisory to identify affected instances since no version range is given here. If patching must wait, restrict external access to the JSON web services endpoints and monitor for exploitation, given the in-the-wild status and 99.9% EPSS.

9.8100% KEV PoC
  • Liferay Portal
large≈20,000-40,000 internet-exposed Liferay Portal instances (public internet-wide scan counts)
CVE-2021-3007
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized

NVD description · AI analysis pending
9.875% PoC ×2
  • getlaminas laminas-http
  • getlaminas zend framework

Indicators of compromiseAll →

TypeIndicatorContext
domaingxbrowser.neton installed. "The malware, downloaded from the site hxxp://gxbrowser[.]net, is an obfuscated Python script which contains polymorphi
urlhttp://gxbrowser[d version installed. "The malware, downloaded from the site hxxp://gxbrowser[.]net, is an obfuscated Python script which contains polymor
Full article552 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 19, 2021

An ongoing malware campaign has been found exploiting recently disclosed vulnerabilities in network-attached storage (NAS) devices running on Linux systems to co-opt the machines into an IRC botnet for launching distributed denial-of-service (DDoS) attacks and mining Monero cryptocurrency.

The attacks deploy a new malware variant called "FreakOut" by leveraging critical flaws fixed in Laminas Project (formerly Zend Framework) and Liferay Portal as well as an unpatched security weakness in TerraMaster, according to Check Point Research's new analysis published today and shared with The Hacker News.

Attributing the malware to be the work of a long-time cybercrime hacker — who goes by the aliases Fl0urite and Freak on HackForums and Pastebin at least since 2015 — the researchers said the flaws — CVE-2020-28188, CVE-2021-3007, and CVE-2020-7961 — were weaponized to inject and execute malicious commands in the server.

Regardless of the vulnerabilities exploited, the end goal of the attacker appears to be to download and execute a Python script named "out.py" using Python 2, which reached end-of-life last year — implying that the threat actor is banking on the possibility that that victim devices have this deprecated version installed.

"The malware, downloaded from the site hxxp://gxbrowser[.]net, is an obfuscated Python script which contains polymorphic code, with the obfuscation changing each time the script is downloaded," the researchers said, adding the first attack attempting to download the file was observed on January 8.

And indeed, three days later, cybersecurity firm F5 Labs warned of a series of attacks targeting NAS devices from TerraMaster (CVE-2020-28188) and Liferay CMS (CVE-2020-7961) in an attempt to spread N3Cr0m0rPh IRC bot and Monero cryptocurrency miner.

An IRC Botnet is a collection of machines infected with malware that can be controlled remotely via an IRC channel to execute malicious commands.

In FreakOut's case, the compromised devices are configured to communicate with a hardcoded command-and-control (C2) server from where they receive command messages to execute.

The malware also comes with extensive capabilities that allow it to perform various tasks, including port scanning, information gathering, creation and sending of data packets, network sniffing, and DDoS and flooding.

Furthermore, the hosts can be commandeered as a part of a botnet operation for crypto-mining, spreading laterally across the network, and launching attacks on outside targets while masquerading as the victim company.

With hundreds of devices already infected within days of launching the attack, the researchers warn, FreakOut will ratchet up to higher levels in the near future.

For its part, TerraMaster is expected to patch the vulnerability in version 4.2.07. In the meantime, it's recommended that users upgrade to Liferay Portal 7.2 CE GA2 (7.2.1) or later and laminas-http 2.14.2 to mitigate the risk associated with the flaws.

"What we have identified is a live and ongoing cyber attack campaign targeting specific Linux users," said Adi Ikan, head of network cybersecurity Research at Check Point. "The attacker behind this campaign is very experienced in cybercrime and highly dangerous."

"The fact that some of the vulnerabilities exploited were just published, provides us all a good example for highlighting the significance of securing your network on an ongoing basis with the latest patches and updates."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/01/freakout-ongoing-botnet-attack.html