Log4Shell attacks expand to nation-state groups from China, Iran, North Korea, and Turkey
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44228 | JNDI Injection Remote Code Execution in Apache Log4j2 (Log4Shell) Apache Log4j2, an extremely widely used Java logging library, fails to protect its JNDI lookup feature against attacker-controlled JNDI-related endpoints (CWE-20, CWE-502), so crafted text processed by the logger causes the Java runtime to fetch and load attacker-supplied objects, leading to remote code execution. The flaw is triggered whenever attacker-controlled input reaches the logging API and is parsed for JNDI lookups, a pattern common in web servers and enterprise Java applications that log user-supplied fields such as headers or form values. Successful exploitation yields arbitrary code execution under the privileges of the affected application, giving attackers a foothold for lateral movement, data theft, and ransomware deployment. Any Java application or product that ships or bundles an affected Apache Log4j2 release is exposed, making this one of the most broadly deployed vulnerabilities ever disclosed. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-12-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days. Do: Inventory all Java applications and dependencies for Apache Log4j2 and apply the vendor's patched updates, or remove affected assets from the network, as required by CISA's KEV catalog. Where updates are not yet available, use the temporary mitigations in CISA's ED-22-02 recommended-mitigation guidance, such as disabling message lookups, only until patches are applied. Prioritize internet-facing and business-critical systems and hunt for exploitation activity given known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×9 |
| masshundreds of millions of Java applications/devices, with hundreds of thousands of internet-exposed services |
Full article397 words · extracted from therecord.media · click to collapse
Nation-state groups from China, Iran, North Korea, and Turkey are now abusing the Log4Shell (CVE-2021-44228) vulnerability to gain access to targeted networks, Microsoft said on Tuesday. "This activity ranges from experimentation during development, integration of the vulnerability to in-the-wild payload deployment, and exploitation against targets to achieve the actor's objectives," the company said in an update on its Log4Shell guidance blog post. Known threat actors linked to Log4Shell attacks include Phosphorus (Iran) and Hafnium (China). Microsoft did not name the threat actors operating out of North Korea and Turkey. "For example, MSTIC has observed PHOSPHORUS, an Iranian actor that has been deploying ransomware, acquiring and making modifications of the Log4j exploit," Microsoft said yesterday. "In addition, HAFNIUM, a threat actor group operating out of China, has been observed utilizing the vulnerability to attack virtualization infrastructure to extend their typical targeting. In these attacks, HAFNIUM-associated systems were observed using a DNS service typically associated with testing activity to fingerprint systems," the company added. In addition, Microsoft said it has also observed multiple threat actors who serve as initial access brokers for ransomware gangs using the Log4Shell exploit to gain a foothold on corporate networks. These groups typically sell access to these hacked networks to ransomware gangs, and Microsoft worries that Log4Shell may contribute to a spike in ransomware attacks over the coming months. The company's fears aren't an isolated sentiment, having also been echoed by many security experts over the past few days since the Log4Shell vulnerability came to light. A first ransomware operation leveraging the Log4Shell exploit was spotted on Sunday. Named Khonsari ("bloodshed" in Persian), the ransomware was categorized as a low-effort skidware that tried to frame a person of Iranian descent living in Louisiana as the attacker, providing no way for victims to recover encrypted files. This attack was one of the several malware operations that have targeted the Log4Shell exploit and used it to spread to vulnerable systems. Over 60 variations of the Log4Shell exploit have been observed in the wild so far, and attacks have been linked to DDoS botnets, crypto-mining operations, and commodity malware like StealthLoader.
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/log4shell-attacks-expand-to-nation-state-groups-from-china-iran-north-korea-and-turkey