ZeroHour
Security Affairspublished ()ingested @securityaffairs

iSight Partners - Sandworm is involved Ukrainian power outage

criticalThreat actorimportance 60CVE-2013-3906

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2013-3906
Memory Corruption RCE in Microsoft Graphics Component (Actively Exploited)

Microsoft's Graphics Component contains a memory corruption vulnerability that can allow remote code execution when the component processes maliciously crafted graphics content, typically delivered inside documents or other rendered content. An attacker who successfully triggers the flaw gains the ability to execute arbitrary code on the target system in the context of the current user, inheriting that user's privileges. Any Microsoft Windows system running an affected version of the Graphics Component is exposed, since the component is part of the Windows platform and is reachable through normal document and image rendering. The flaw was exploited as a zero-day in targeted attacks — notably by the Sandworm threat group against Ukrainian government and NATO-related targets, per iSight Partners reporting — and was addressed in Microsoft's December 2013 security updates. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-15, and EPSS currently assigns an 85% probability of exploitation within 30 days (100th percentile).

Do: Apply the vendor's December 2013 security updates covering the Graphics Component (MS13-098) to all Windows systems, prioritizing legacy machines that may have never received the patch, and verify KEV remediation compliance if you are a federal agency. Because exploitation vectors historically involved malicious document rendering, reinforce email filtering and Office attack-surface reduction (e.g., blocking untrusted embedded graphics/objects) on any systems that remain unpatched.

85% KEV
  • Microsoft Graphics Component
mass≈1 billion+ Windows installations carried the component at the time of disclosure; residual exposure is limited to systems never patched with the December 2013…
Full article815 words · extracted from securityaffairs.com · click to collapse

The Russian Sandworm APT group if the first suspect for the Ukrainian power outage, states experts at eiSight Partners.

According to a report published by experts at eiSight Partners the cyber attack against a Ukraine power station has been managed by a Russian group called Sandworm.

A few days ago experts at ESET reported the existence of a new component in the BlackEnergy trojan, the KillDisk module which is capable of destroying some 4000 different file types and rendering machines unbootable.

“ESET has recently discovered that the BlackEnergy trojan was recently used as a backdoor to deliver a destructive KillDisk component in attacks against Ukrainian news media companies and against the electrical power industry. ” states the blog post published by ESET.

Now experts at iSIGHT’s  linked the KillDisk to the BlackEnergy 3 used by Sandworm in the past.

“Last week iSIGHT’s sources provided us with the same KillDisk malware published by Rob Lee of SANS and Dragos Security. As ESET has, we place this malware within the greater context of activity tied to BlackEnergy 3, which we believe is Sandworm Team. We believe this KillDisk malware is related to the destructive malware leveraged during Ukrainian elections in October. At the time, CERT-UA connected that incident to BlackEnergy 3. Symantec has since verified those claims. Furthermore, iSIGHT’s own sources indicate that BlackEnergy 3 malware was deployed on at least one of the Ukrainian power systems affected by KillDisk.”  wrote John Hultquist, director of cyberespionage analysis at iSight Partners.

Blackenergy power outage

The hackers used the highly destructive malware to compromise the systems at three regional power authorities in Ukraine. The attacks caused blackouts across the Ivano-Frankivsk region of Ukraine on 23rd December.

According to a Ukrainian media TSN, the power outage was caused by a destructive malware that disconnected electrical substations.

Also in this case, hackers launched a spear-phishing campaign across the Ukrainian power authorities to spread the destructive variant to the BlackEnergy leveraging on Microsoft Office documents.

The attribution of the attack is not simple, we are only aware that the BlackEnergy malware has a Russian origin and that Russian has a political dispute with the Ukraine that had repercussion also on the cyberspace.

My readers have already read about Sandworm, according to a previous report issued by iSIGHT, the APT has been active since at least 2009. In 2014, the Russian group targeted a Polish energy firm, a Western European government agency and also a French telecommunications firm.

The experts began the investigation in late 2013 when the NATO alliance was targeted by the SandWorm hacking team with exploits other than the zero-day, but they discovered the critical zero-day  in August 2104, when the group targeted the Ukrainian government, in the lead-up to the NATO summit in Wales.

“In late August, while tracking the Sandworm Team, iSIGHT discovered a spear-phishingcampaign targeting the Ukrainian government and at least one United States organization. Notably, these spear-phishing attacks coincided with the NATO summit on Ukraine held in Wales.” states the report published by iSIGHT.

Security experts speculated that the intensification of the cyber dispute  between Russian and Ukraine could have increased the likelihood to discover operations that went under the radar for so long.

Below chronological details provided by the researchers on the Sandworm activity:

  • The NATO alliance was targeted as early as December 2013 with exploits other than the zero-day
  • GlobSec attendees were targeted in May of 2014 with exploits other than the zero-day
  • June 2014
    • Broad targeting against a specific Western European government
    • Targeting of a Polish energy firm using CVE-2013-3906
    • Targeting of a French telecommunications firm using a BlackEnergy variant configured with a Base64-encoded reference to the firm

The SandWorm hacking team sent spear-phishing emails with malicious attachments to compromise the victim’s machine, the threat actors mentioned a global security forum on Russia and a purported list of Russian terrorists.

Another element that suggests Russia is responsible for the cyber espionage campaign are codes discovered on  the C&C server, located in Germany, that had not been properly secured and that contains Russian-language computer files that had been uploaded by the hackers.

“They could have closed it off, and they didn’t,” he said of the server. “It was poor operational security.”

The Ukraine’s CERT already reported  numerous attacks against Ukrainian media leveraging the BlackEnergy malware, the offensive was intensified in concomitance the local elections.

“Recently, a number of Ukrainian media in the days of local elections was attacked by unknown hackers.” states the UA-CERT “In general, I would like to note that the threat has the character of a well-planned order to show the ability of abnormal function compromised corporate media networks by using a tool such hackers as Black Energy (Win32 / Rootkit.BlackEnergy, Backdoor.Win64.Blakken), which is used to conducting APT-attacks.”

Stay Tuned!

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Black Energy, Sandworm)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/43413/malware/sandworm-apt-ukrainian-power-outage.html