ZeroHour
Security Affairspublished ()ingested @securityaffairs

UK, US agencies warn of brute

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0688
RCE in Microsoft Exchange Server from Shared Install-Time Validation Keys

CVE-2020-0688 is a remote code execution vulnerability in Microsoft Exchange Server caused by the validation key not being uniquely created at install time, leaving deployments with a predictable, shared key (CWE-287, improper authentication). A remote attacker who can reach an affected Exchange server and knows the common install-time key can supply maliciously crafted, cryptographically signed payloads that the server trusts, triggering code execution without needing per-server secrets. Successful exploitation gives the attacker code execution on the Exchange server, which can be used to access mail data, move laterally, and stage follow-on activity; CISA notes known use in ransomware campaigns. All organizations running the affected on-premises Microsoft Exchange Server are in scope per CISA's listing, though the affected version range is not specified in the source data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, and EPSS rates 30-day exploitation probability at 100% (top percentile).

Do: Apply Microsoft's Exchange security updates addressing CVE-2020-0688 (released in February 2020) to every on-premises Exchange server, per CISA's required action. As an interim mitigation, configure a unique ASP.NET machineKey in each Exchange server's web.config instead of the default shared install-time key, and hunt for indicators of exploitation given the known ransomware use.

8.8100% KEV ransomware PoC ×2
  • Microsoft Exchange Server
masshundreds of thousands of on-premises Exchange servers (≈500,000)
CVE-2020-17144
Remote Code Execution in Microsoft Exchange Server via Cmdlet Argument Validation

CVE-2020-17144 is a remote code execution vulnerability in Microsoft Exchange Server caused by improper validation of cmdlet arguments; the associated weakness class (CWE-502, deserialization of untrusted data) indicates that improperly validated attacker-supplied arguments are deserialized and executed by the server. An attacker triggers the flaw by sending specially crafted cmdlet arguments to a vulnerable Exchange server, causing attacker-controlled code to run on the server. Successful exploitation yields remote code execution on the Exchange host, which could provide command execution in the Exchange service context, access to mail data, and a foothold for further compromise. Organizations running affected on-premises Microsoft Exchange Server deployments are affected; the available data lists 'Microsoft Exchange Server' without specifying version ranges, and cloud-based Exchange Online is not implicated by this server-side flaw. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03, EPSS is high at 36.5% (98th percentile), no public PoC is known, and any association with ransomware is unknown.

Do: Inventory all on-premises Exchange servers and verify their current patch level, then apply Microsoft's Exchange security updates containing this fix (released in the November 2020 Patch Tuesday) per the CISA required action. Until patched, restrict access to Exchange management/cmdlet interfaces and review Exchange and PowerShell logs for unexpected cmdlet or deserialization activity. Given the confirmed in-the-wild exploitation (KEV) and elevated EPSS (36.5%), treat this as a high-priority patch even though no public PoC exists.

8.437% KEV
  • Microsoft Exchange Server
masshundreds of thousands of on-premises Exchange deployments worldwide
Full article503 words · extracted from securityaffairs.com · click to collapse

US and UK cybersecurity agencies said the Russia-linked APT28 group is behind a series of large-scale brute-force attacks.

US and UK cybersecurity agencies published a joint alert about a series of large-scale brute-force conducted by the Russia-linked APT28 group.

The joint alert was published by the US National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), the US Federal Bureau of Investigation (FBI), and the UK’s National Cyber Security Centre (NCSC).

The attacks took place between mid-2019 and early 2021, the Russia-linked threat actor used a Kubernetes cluster to conduct anonymized brute force access against hundreds of government organizations and businesses worldwide, including think tanks, defense contractors, energy firms.

The attackers remained under the radar by routing brute force attacks through the TOR network and commercial VPN services, including CactusVPN, IPVanish, NordVPN, ProtonVPN, Surfshark, and WorldVPN. Authentication attempts that did not use TOR or a VPN service were also occasionally delivered directly to targets from nodes in the Kubernetes cluster

The government experts attribute the attacks to Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS), military unit 26165.

“Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments” details how the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) has targeted hundreds of U.S. and foreign organizations using brute force access to penetrate government and private sector victim networks.” reads the advisory published by the NSA.

The advisory provided details about the tactics, techniques, and procedures (TTPs) associated with GTsSS.

The APT group mainly targeted organizations using Microsoft Office 365 cloud services, along with targets using other service providers and on-premises email servers. Experts speculate the activity is still ongoing.

The attackers carried out brute force attacks to discover valid credentials, in some cases, they also used credentials leaked in past breaches or guessed with variations of the most common passwords. Expert pointed out that the GTsSS uniquely leveraged software containers to easily scale its brute force attempts.

Upon discovering valid credentials, the GTsSS exploited various publicly known vulnerabilities (Microsoft Exchange flaws CVE-2020-0688 and CVE-2020-17144) to gain further access into target networks. The nation-state actors were able to evade defenses, collect and exfiltrate various information in the networks.

“The actors used a combination of known TTPs in addition to their password spray operations to exploit target networks, access additional credentials, move laterally, and collect, stage, and exfiltrate data, as illustrated in the figure below.” reads the joint report. “The actors used a variety of protocols, including HTTP(S), IMAP(S), POP3, and NTLM. The actors also utilized different combinations of defense evasion TTPs in an attempt to disguise some components of their operations; however, many detection opportunities remain viable to identify the malicious activity.”

The report also includes indicators of compromise (IoCs) for the brute-force attacks conducted by the APT28 cyberespionage group. The document also provides Yare Rules and mitigations.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Russia)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/119595/apt/russia-apt-brute-force-attacks.html