Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-12356 | Unauthenticated Command Injection in BeyondTrust Privileged Remote Access/Remote Support BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an unauthenticated command injection flaw (CWE-77) that allows a remote attacker to inject commands that are executed as a site user. The vulnerability is network-facing with low attack complexity and requires no privileges or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), so any attacker who can reach the affected PRA/RS interface can trigger it. Successful exploitation yields arbitrary command execution in the context of the site user, with high impact ratings for confidentiality, integrity, and availability. Any organization running BeyondTrust PRA or RS — particularly where those remote-access/remote-support services are exposed to the internet — is affected; the available data does not specify affected version ranges. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-19, carries an 88% EPSS probability of exploitation within 30 days (100th percentile), and was reportedly used in the breach of the U.S. Treasury alongside a PostgreSQL vulnerability. Do: Apply BeyondTrust's patches or vendor-specified mitigations immediately — remediation is mandatory for U.S. federal agencies under the KEV listing, and the source data does not include fixed build numbers, so confirm the correct upgrade version in BeyondTrust's security bulletin. As an interim measure, restrict or remove internet exposure of PRA/RS endpoints and hunt for signs of exploitation (unexpected commands executed as the site user), noting this flaw was used in the U.S. Treasury intrusion. If mitigations are unavailable, CISA's required action is to discontinue use of the product. | 9.8 | 88% | KEV PoC |
| moderate≈ a few thousand internet-exposed PRA/RS instances (order-of-magnitude estimate from public internet scans) | |
| CVE-2024-12686 | OS Command Injection in BeyondTrust Privileged Remote Access and Remote Support CVE-2024-12686 is an OS command injection flaw (CWE-78) in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) that is reachable over the network but requires the attacker to already hold administrative privileges in the product. By injecting commands through an administrative function, the attacker gets arbitrary commands executed on the underlying host as the site user, producing high impact to confidentiality, integrity, and availability in that context. Organizations running BeyondTrust PRA or RS — commonly deployed for privileged remote support and help-desk access — are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-13, confirming exploitation in the wild, and EPSS assigns a 13.8% probability of exploitation within 30 days (96th percentile). The flaw arrives amid a broader wave of BeyondTrust attacks, including the related zero-day CVE-2024-12356 tied to a compromised API key that exposed 17 SaaS customers and was used by a China-linked actor against U.S. Treasury systems, and reported chaining with a PostgreSQL flaw in targeted attacks. Do: Upgrade all PRA and RS deployments to the fixed releases identified in BeyondTrust's security bulletin for CVE-2024-12686 (including any SaaS instances managed by BeyondTrust), and apply the mitigations required by the CISA KEV entry if patching must be deferred. Because exploitation requires administrative access, review and rotate privileged and API credentials — especially given the related API-key compromise behind CVE-2024-12356 — restrict administrative console exposure to trusted networks, and check logs for unexpected commands executed as the site user. | 7.2 | 14% | KEV |
| moderatelikely on the order of thousands of exposed PRA/RS instances (estimate; no install counts in source data) |
Full article565 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 31, 2024Vulnerability / Incident Response
The United States Treasury Department said it suffered a "major cybersecurity incident" that allowed suspected Chinese threat actors to remotely access some computers and unclassified documents.
"On December 8, 2024, Treasury was notified by a third-party software service provider, BeyondTrust, that a threat actor had gained access to a key used by the vendor to secure a cloud-based service used to remotely provide technical support for Treasury Departmental Offices (DO) end users," the department said in a letter informing the Senate Committee on Banking, Housing, and Urban Affairs.
"With access to the stolen key, the threat actor was able to override the service's security, remotely access certain Treasury DO user workstations, and access certain unclassified documents maintained by those users."
The federal agency said it has been working with the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), and that available evidence points to it being the work of an unnamed state-sponsored Advanced Persistent Threat (APT) actor from China.
The Treasury Department further said that it has taken the BeyondTrust service offline, adding there is no evidence that the threat actors have access to the environment. It did not share any indicators of compromise that China is responsible for the hack, nor specify when and for how long the breach occurred.
China's foreign ministry spokesperson Mao Ning denied claims of targeting the Treasury Department. "On this kind of unwarranted and groundless allegations, we've made clear our position more than once. China opposes all forms of hacking, and in particular, we oppose spreading China-related disinformation motivated by political agenda," Ning said.
Earlier this month, BeyondTrust revealed that it was the victim of a digital intrusion that allowed bad actors to breach some of its Remote Support SaaS instances.
The company said its investigation into the incident found that the attackers gained access to a Remote Support SaaS API key that allowed them to reset passwords for local application accounts. BeyondTrust has yet to reveal how the key was obtained.
"BeyondTrust immediately revoked the API key, notified known impacted customers, and suspended those instances the same day while providing alternative Remote Support SaaS instances for those customers," it said.
The probe has also uncovered two security flaws in Privileged Remote Access (PRA) and Remote Support (RS) products (CVE-2024-12356, CVSS score: 9.8 and CVE-2024-12686, CVSS score: 6.6), the former of which has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.
The disclosure comes as several U.S. telecommunication providers have found themselves in the crosshairs of another Chinese state-sponsored threat actor named Salt Typhoon.
Update
A new report from the Washington Post published on January 1, 2024, revealed that the December cyber attack by Chinese threat actors targeting the Treasury Department breached the Office of Foreign Assets Control (OFAC) as well as the Office of the Treasury Secretary, citing anonymous U.S. officials.
"The targeting of the Office of Foreign Assets Control (OFAC) as well as the Office of the Treasury Secretary – developments not previously reported – reflects Beijing's determination to acquire intelligence on its most significant rival in the global competition for power and influence," the officials were quoted as saying.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/12/chinese-apt-exploits-beyondtrust-api.html