ZeroHour
CyberScooppublished ()ingested @Bing_Chris

Roy Moore scandal used for phishing schemes aimed at U.S. law firms

criticalPhishing & fraud exploited in the wildimportance 60CVE-2017-0199

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-0199
Remote Code Execution in Microsoft Office and WordPad via crafted document files

CVE-2017-0199 is a remote code execution vulnerability in Microsoft Office and WordPad that stems from improper parsing of specially crafted files. Attackers trigger it by getting a user to open a malicious document, after which attacker-controlled code executes with the privileges of the logged-in user. Anyone running the affected Microsoft Office or WordPad software is exposed, and CISA notes the flaw has been leveraged in ransomware campaigns; no CVSS score is available in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), indicating active, ongoing exploitation.

Do: Apply Microsoft's security updates for Office and Windows per vendor instructions, as required by CISA's KEV catalog; the flaw was publicly reported as fixed in Microsoft's April 2017 security updates. Until patched, treat unsolicited Office documents and email attachments as high-risk, since exploitation requires a user to open a crafted file. Verify that all Office and WordPad installations across the estate—especially endpoints that handle untrusted documents—have received the update.

7.8100% KEV ransomware PoC ×6
  • Microsoft Office
  • Microsoft WordPad
masshundreds of millions of Office installations worldwide (exact count unknown)
Full article1,003 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

A group loosely connected to China is trying to capitalize on the scandal surrounding the special election in Alabama.

roy moore
(Roy moore for senate)

Since at least June, Chinese hackers have been actively targeting a shortlist of multinational law firms in an apparent effort to spy on lawyers and steal confidential information, according to cybersecurity firm FireEye.

The hacking group, which is known as APT19, will often design phishing campaigns that contain references to pertinent, high-profile U.S. news stories. Most recently, these booby-trapped emails have separately mentioned U.S. Senate candidate Roy Moore, disgraced Hollywood producer Harvey Weinstein and former presidential candidate Hillary Clinton.

The hacking group has been loosely linked to China.

FireEye says APT19 crafted the subject line “FW: Roy Moore scandal ignites fundraising explosion for Democratic challenger Doug Jones” to seemingly capitalize on the contentious campaign to fill the vacant senate seat in Alabama. Moore, 70, has been accused of making unwanted sexual advances toward multiple teenage girls when he was in his 30s.

It’s relatively common for hackers to leverage public events to lure targets into clicking a suspicious email or link. Other groups known to leverage this technique include Russian groups APT28 and APT29, more commonly known as “Fancy Bear” and “Cozy Bear.” APT28 used the technique in the aftermath of a terrorist attack in New York City earlier this year.

FireEye has evidence of at least three law firms being repeatedly and continuously targeted as part of APT19’s latest activity. These organizations are based in the U.S. but have offices globally, including in China. All three boast business internationally, offering various different legal practices.

Ben Read, an analyst with FireEye, told CyberScoop the most recent wave of APT19’s phishing emails had been detected last week. It is the fourth known wave of related malicious emails following a barrage of similar messages in June, October and then again in mid-November.

In each case, the emails carried malware inside a Microsoft word document, Read said. When opened, the document would covertly download an open-source backdoor onto the victim’s computer before then establishing a connection to the attacker’s own server. This backdoor can provide APT19 with wide-access to a compromised device as well as the network it is connected to.

All four identified waves of phishing emails targeted the same group of law firms. FireEye’s visibility into the threat is limited to its customer base, meaning that a variety of other APT19 targets may exist.

“It’s difficult to say what they’re after because the lures are so broadly written and we’re stopping them at the perimeter, before they really get a chance to do much,” said Read. “It’s feasible that APT19 is looking to steal financial documents, including information about business mergers and acquisitions which could be worth a lot.”

FireEye first detailed APT19’s interest in law firms in June. Read says the group has continued to use the same toolset since June although in some instances they’ve slightly tweaked their intrusion techniques to avoid detection. The original sighting in June saw APT19 use a well-known and outdated Microsoft office vulnerability (CVE-2017-0199) to deliver malware.

“Based on what we can observe, the targets are mostly the same every time (major U.S.-based law firms),” said FireEye analyst Ian Ahl. “The emails all originate from an APT19 owned domain, but the sender username is often changed.”

Read said it remains unclear whether APT19 is in any way affiliated with the Chinese government.

Last week, the Justice Department indicted three Chinese hackers who were at one point connected to a group also tracked by FireEye, named APT3. While there’s some indication those indicted individuals worked for a state run intelligence agency, the trio regularly used what appeared to be a Chinese shell company to obfuscate the nature of their offensive operations. Experts say it’s typical for Beijing to use a mix of contractors and fake companies to hide traditional intelligence gathering efforts which are in reality led by state agencies.

More Scoops

A health worker prepares a dose of the Covaxin vaccine against the Covid-19 coronavirus at a vaccination centre in New Delhi on September 29, 2021. (Photo by SAJJAD HUSSAIN/AFP via Getty Images)

Suspected Chinese hackers masqueraded as Indian government to send COVID-19 phishing emails

The group had a prolific 2020, and has stayed busy in 2021.

Washington Monument
(Getty Images)

U.S. intelligence community details destructive cyber capabilities, growing influence threats

Secretary of State Michael R. Pompeo, Secretary of the Treasury Steven Mnuchin,then-Secretary of Defense Mark Esper, Secretary of Commerce Wilbur Ross, U.N. Representative Kelly Craft, and national security adviser Robert O’Brien chat before delivering remarks to the media at the U.S. Department of State in Washington, D.C., on Sept. 21, 2020. (State Department)

US investigates suspected cyber-espionage campaign against government agencies dating back months

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/roy-moore-scandal-phishing-attacks-apt19-fireeye-harvey-weinstein/