Roy Moore scandal used for phishing schemes aimed at U.S. law firms
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0199 | Remote Code Execution in Microsoft Office and WordPad via crafted document files CVE-2017-0199 is a remote code execution vulnerability in Microsoft Office and WordPad that stems from improper parsing of specially crafted files. Attackers trigger it by getting a user to open a malicious document, after which attacker-controlled code executes with the privileges of the logged-in user. Anyone running the affected Microsoft Office or WordPad software is exposed, and CISA notes the flaw has been leveraged in ransomware campaigns; no CVSS score is available in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), indicating active, ongoing exploitation. Do: Apply Microsoft's security updates for Office and Windows per vendor instructions, as required by CISA's KEV catalog; the flaw was publicly reported as fixed in Microsoft's April 2017 security updates. Until patched, treat unsolicited Office documents and email attachments as high-risk, since exploitation requires a user to open a crafted file. Verify that all Office and WordPad installations across the estate—especially endpoints that handle untrusted documents—have received the update. | 7.8 | 100% | KEV ransomware PoC ×6 |
| masshundreds of millions of Office installations worldwide (exact count unknown) |
Full article1,003 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A group loosely connected to China is trying to capitalize on the scandal surrounding the special election in Alabama.
Since at least June, Chinese hackers have been actively targeting a shortlist of multinational law firms in an apparent effort to spy on lawyers and steal confidential information, according to cybersecurity firm FireEye.
The hacking group, which is known as APT19, will often design phishing campaigns that contain references to pertinent, high-profile U.S. news stories. Most recently, these booby-trapped emails have separately mentioned U.S. Senate candidate Roy Moore, disgraced Hollywood producer Harvey Weinstein and former presidential candidate Hillary Clinton.
The hacking group has been loosely linked to China.
FireEye says APT19 crafted the subject line “FW: Roy Moore scandal ignites fundraising explosion for Democratic challenger Doug Jones” to seemingly capitalize on the contentious campaign to fill the vacant senate seat in Alabama. Moore, 70, has been accused of making unwanted sexual advances toward multiple teenage girls when he was in his 30s.
It’s relatively common for hackers to leverage public events to lure targets into clicking a suspicious email or link. Other groups known to leverage this technique include Russian groups APT28 and APT29, more commonly known as “Fancy Bear” and “Cozy Bear.” APT28 used the technique in the aftermath of a terrorist attack in New York City earlier this year.
FireEye has evidence of at least three law firms being repeatedly and continuously targeted as part of APT19’s latest activity. These organizations are based in the U.S. but have offices globally, including in China. All three boast business internationally, offering various different legal practices.
Ben Read, an analyst with FireEye, told CyberScoop the most recent wave of APT19’s phishing emails had been detected last week. It is the fourth known wave of related malicious emails following a barrage of similar messages in June, October and then again in mid-November.
In each case, the emails carried malware inside a Microsoft word document, Read said. When opened, the document would covertly download an open-source backdoor onto the victim’s computer before then establishing a connection to the attacker’s own server. This backdoor can provide APT19 with wide-access to a compromised device as well as the network it is connected to.
All four identified waves of phishing emails targeted the same group of law firms. FireEye’s visibility into the threat is limited to its customer base, meaning that a variety of other APT19 targets may exist.
“It’s difficult to say what they’re after because the lures are so broadly written and we’re stopping them at the perimeter, before they really get a chance to do much,” said Read. “It’s feasible that APT19 is looking to steal financial documents, including information about business mergers and acquisitions which could be worth a lot.”
FireEye first detailed APT19’s interest in law firms in June. Read says the group has continued to use the same toolset since June although in some instances they’ve slightly tweaked their intrusion techniques to avoid detection. The original sighting in June saw APT19 use a well-known and outdated Microsoft office vulnerability (CVE-2017-0199) to deliver malware.
“Based on what we can observe, the targets are mostly the same every time (major U.S.-based law firms),” said FireEye analyst Ian Ahl. “The emails all originate from an APT19 owned domain, but the sender username is often changed.”
Read said it remains unclear whether APT19 is in any way affiliated with the Chinese government.
Last week, the Justice Department indicted three Chinese hackers who were at one point connected to a group also tracked by FireEye, named APT3. While there’s some indication those indicted individuals worked for a state run intelligence agency, the trio regularly used what appeared to be a Chinese shell company to obfuscate the nature of their offensive operations. Experts say it’s typical for Beijing to use a mix of contractors and fake companies to hide traditional intelligence gathering efforts which are in reality led by state agencies.
More Scoops
Suspected Chinese hackers masqueraded as Indian government to send COVID-19 phishing emails
The group had a prolific 2020, and has stayed busy in 2021.
U.S. intelligence community details destructive cyber capabilities, growing influence threats
US investigates suspected cyber-espionage campaign against government agencies dating back months
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/roy-moore-scandal-phishing-attacks-apt19-fireeye-harvey-weinstein/