Visualizing RedKit Exploits
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2010-0188 | Arbitrary Code Execution in Adobe Reader and Acrobat via Malicious PDF Handling CVE-2010-0188 is an unspecified code-injection (CWE-94) flaw in Adobe Reader and Acrobat that allows attackers to cause a denial of service or possibly execute arbitrary code on the victim's machine. It is triggered when an affected application processes a maliciously crafted PDF document, typically delivered as an email attachment or downloaded from a website, so simply viewing the file with vulnerable software is enough to expose the user. A successful attack gives the attacker code execution in the context of the logged-on user, which can be leveraged to install malware or ransomware. Anyone running Adobe Reader or Acrobat is affected; CISA lists the products without published version ranges, so all Adobe deployments should be treated as potentially in scope. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-03-03) with known ransomware use, and EPSS assigns an 88.2% probability of exploitation within 30 days (100th percentile). Do: Apply updates per vendor instructions: install the Adobe security update that fixes CVE-2010-0188 on any legacy Acrobat/Reader deployment and migrate unsupported installations to a currently supported Acrobat/Reader release. Given the known ransomware association, hunt for signs of compromise such as suspicious PDF attachments opened around malware activity, and block or sandbox PDFs at email and web gateways. Verify no critical hosts or automated workflows still depend on outdated Reader/Acrobat components for PDF processing. | — | 88% | KEV ransomware |
| masshundreds of millions of installed copies (Reader/Acrobat historically shipped as the default PDF handler on most Windows PCs; exact count of still-vulnerable… | |
| CVE-2012-0507 | Type Confusion RCE in Oracle Java SE Concurrency Component CVE-2012-0507 is an 'incorrect type' (type-confusion) vulnerability in the Concurrency component of Oracle's Java Runtime Environment that corrupts memory when crafted Java content is processed. It is triggered by running malicious Java content — classically via the browser Java plugin or an exploited Java application — allowing an attacker to execute arbitrary code with the privileges of the Java process. Anyone running an affected Oracle Java SE installation is exposed, which historically included the vast majority of desktops and many servers, with 2012-era campaigns hitting Mac users via Java exploits (e.g., the SabPub backdoor) and drive-by exploit kits. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) with known ransomware use, and EPSS assigns a 98.1% probability of exploitation within 30 days (100th percentile). CVSS has not been scored in the source data, but the combined KEV/EPSS signal marks this as actively and widely exploited. Do: Apply Oracle's Java SE updates per CISA's required action — Oracle shipped the fix in its February 2012 Critical Patch Update, so any current, fully patched Java release clears the flaw; verify no legacy unpatched Java builds (including Apple-delivered Java on macOS, given the 2012 OS X exploitation campaigns) remain on endpoints. Remove or disable the Java browser plugin where it is not required, and restrict execution of untrusted applets and Java Web Start content. | — | 98% | KEV ransomware |
| mass≈1 billion+ Java installations worldwide (desktop/server JRE and browser plugin deployments) | |
| CVE-2013-0431 | Security Sandbox Bypass in Oracle Java Runtime Environment (JRE) CVE-2013-0431 is an unspecified vulnerability in the Oracle Java Runtime Environment (JRE) that allows remote attackers to bypass the Java security sandbox. It is triggered when a user running an affected, unpatched JRE loads attacker-supplied Java content, such as a malicious web applet delivered via a drive-by download (historically distributed via exploit kits, per related reporting on RedKit). Bypassing the sandbox lets the attacker escape Java's restricted execution environment, enabling arbitrary code execution on the victim system and follow-on malware or ransomware installation. Any system running a vulnerable version of Oracle JRE is affected, particularly desktops with the Java browser plugin enabled; the available data does not specify exact affected version ranges. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25) with known ransomware use and a 90% EPSS exploitation probability, indicating active in-the-wild exploitation; no public proof-of-concept is cataloged. Do: Upgrade the JRE to a release patched by Oracle per the vendor's Critical Patch Update instructions, as required by the CISA KEV listing. Where Java in the browser is not needed, disable or remove the Java browser plugin to reduce drive-by applet exposure. Check endpoints running older Java builds for signs of drive-by exploitation and ransomware precursor activity. | — | 90% | KEV ransomware |
| masshundreds of millions of endpoints (Java is deployed across most enterprise desktops and, per vendor claims, billions of devices) |
Full article391 words · extracted from recordedfuture.com · click to collapse
The private but popular RedKit exploit kit appears to be experiencing a resurgence based on a report by Kahu Security. Initially spotted back in May 2012, the exploit kit drew attention after cybercriminals used it in drive-by-download attacks from NBC’s compromised website in January 2013 and spam campaigns immediately after the Boston Marathon bombings.
These attacks featured iframes on the compromised websites performing simultaneous actions when rendered in a victim’s web browser. The exploit kit competes against and leverages some of the same exploits as CritXPack, Gong Da, Nuclear Pack, Cool, and Blackhole 2.0. Monitoring developments and adoption of RedKit may be of particular interest given the recent arrest in Russia of Blackhole’s creator.
Cybercriminals have compromised several high profile sites including but not limited to NBC assets and the Segway website to carry out their operations with RedKit. Security experts have also reported pharmaceutical sites and Japanese commercial channels as hosts for RedKit EK servers.
Here’s a more detailed look at addition of RedKit of exploits for specific vulnerabilities, some of which was already very nicely detailed by Malwaggedon, as well as the malware being dropped on successful exploitation and other exploit kits with which it has been partnered:
RedKit EK initially included two exploits – targeting CVE-2010-0188 (Adobe Acrobat and Reader LibTIFF) and CVE-2012-0507 (Java AtomicReferenceArray) – before expanding to include at least nine different exploits. The most recent additions – targeting CVE-2013-0431 and CVE-2013-1493 – were observed in the compromise of Segway’s website.
What’s an example of RedKit in action? On April 16, the Kelihos and Cutwail botnets began sending out spam with subject lines related to the Boston bombing. The emails referred recipients to a site that would compromise their systems via the RedKit exploit kit and install bot software as well as the ZeroAccess trojan used to mine Bitcoin.
Monitor Exploit Developments
Out of the above information discovery conducted using Recorded Future, we put together a list of the nine vulnerabilities, most of them related to Java, exploited by RedKit and set up a monitoring dashboard that displays recently discussed technical details.
Reach out to us at Recorded Future if you’d be interested in real-time alerts on these or related issues, and please also drop by the Naked Security blog by Sophos that has provided two in-depth blog posts on RedKit.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/redkit-exploit-kit-evolution