ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

RansomEXX Group Targets Indian Banking With New Tactics

criticalRansomwareimportance 60CVE-2024-23897

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-23897
Path Traversal in Jenkins CLI Allows File Read and Code Execution

CVE-2024-23897 is a path traversal flaw in the Jenkins Command Line Interface (CLI), the built-in remote-access component of the Jenkins automation server. It is triggered when an attacker submits crafted CLI requests to a Jenkins controller, causing the CLI to resolve paths outside the intended directory and return file contents. The attacker gains limited read access to files on the controller, which can be leveraged toward code execution. Any organization running a Jenkins controller with the CLI enabled — the CLI ships with Jenkins and is commonly left on, including on internet-facing build servers — is affected. Exploitation is confirmed in the wild: the flaw is on the CISA Known Exploited Vulnerabilities catalog (added 2024-08-19) with known ransomware use, and EPSS puts its 30-day exploitation probability at 100%.

Do: Upgrade Jenkins controllers to a fixed release per the vendor advisory, or apply the KEV-required mitigations — notably disabling or restricting access to the CLI — and discontinue use if mitigations are unavailable. Prioritize internet-facing Jenkins instances given known ransomware use, verify your running controller version against the advisory's fixed versions, and hunt for anomalous CLI request activity and signs of file-read reconnaissance on the controller host.

9.8100% KEV ransomware PoC ×3
  • Jenkins Command Line Interface (CLI)
largetens of thousands of internet-exposed Jenkins controllers, plausibly 100,000+ total installations
Full article339 words · extracted from infosecurity-magazine.com · click to collapse

A significant ransomware attack has recently compromised India's banking sector, affecting banks and payment providers. The attack has primarily targeted Brontoo Technology Solutions, a major partner of C-Edge Technologies Ltd, a collaboration between Tata Consultancy Services and State Bank of India. 

According to a new advisory published by CloudSek today, the initial breach occurred through a misconfigured Jenkins server at Brontoo Technology Solutions. Exploiting a known vulnerability (CVE-2024-23897), attackers gained secure shell access by reading private keys due to an open port 22. 

CloudSEK suspects, with moderate certainty, that initial access was brokered by IntelBroker, a threat actor on breach forums, and sold to the RansomEXX group for further exploitation.

Regardless of initial access, however, the ransomware group responsible for this attack is confirmed to be RansomEXX, operating a more sophisticated malware variant, RansomEXX v2.0. Initially known as Defray777, this group has evolved since 2018, rebranding to RansomEXX in 2020. The v2.0 variant reflects advancements in encryption, evasion tactics and payload delivery.

RansomEXX v2.0 employs multiple infection vectors, including phishing and exploiting remote desktop protocol vulnerabilities and weaknesses in VPNs. 

After gaining initial access, the group uses tools like Cobalt Strike and Mimikatz to move laterally within networks and escalate privileges. The ransomware encrypts files using robust algorithms such as RSA-2048 and AES-256, making recovery without the decryption key virtually impossible. Victims receive detailed ransom notes with payment instructions, usually demanding cryptocurrency.

Read more on the exploitation of Jenkins vulnerabilities: CI/CD at Risk as Exploits Released For Critical Jenkins Bug

CloudSEK warned the attack highlights a critical vulnerability in supply chain security. 

“Large organizations with substantial security budgets are more challenging to breach, prompting attackers to exploit the path of least resistance,” the company wrote. “Consequently, supply chain attacks have become increasingly prevalent.”

The company also said that negotiations are currently ongoing with the ransomware group, and the stolen data has not yet been published on their PR website. Given RansomEXX’s history of high ransom demands, a similar approach is anticipated.

Image credit: Harshit Srivastava S3 / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ransomexx-targets-indian-banking/