ZeroHour
Security Affairspublished ()ingested @securityaffairs

CrystalRay operations have scaled 10x to over 1,500 victims

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-18394
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.

NVD description · AI analysis pending
9.832%
  • igniterealtime openfire
CVE-2021-3129
Unauthenticated RCE in Laravel Ignition error-page package (facade/ignition)

Laravel Ignition, the default error-page package bundled with Laravel applications, uses file_get_contents() and file_put_contents() insecurely in its solution-execution feature, allowing unauthenticated remote attackers to read and write arbitrary files on the server. The flaw is triggered by sending a crafted, unauthenticated HTTP request to Ignition's execute-solution endpoint, which is reachable whenever the application runs with debug mode enabled. Attackers can chain the arbitrary file write to execute arbitrary code in the context of the web application, leading to server compromise and, per CISA, ransomware deployment. Any internet-facing Laravel application running a vulnerable version of the Ignition package with debug mode enabled is affected. The vulnerability is known to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-18 with ransomware use confirmed, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile).

Do: Upgrade facade/ignition to 2.5.2 or later on all Laravel applications, or update to a current Laravel release that bundles the fixed package. Ensure production environments run with debug mode disabled and block or restrict the /_ignition/execute-solution endpoint from untrusted access as an interim mitigation. Given confirmed ransomware use, hunt for signs of compromise such as modified environment files, unexpected scheduled tasks, or webshells, and apply the CISA-required mitigations or discontinue use of the product if patching is not possible.

9.8100% KEV ransomware PoC ×3
  • Laravel Ignition (facade/ignition error-page package) Prior to 2.5.2 (CISA data lists affected as 'Laravel Ignition' without a version range; 2.5.2 is the vendor's patched release)
largetens of thousands of internet-facing Laravel apps with debug mode enabled, out of an installed base of hundreds of thousands of Laravel sites
CVE-2022-44877
Remote OS Command Injection in CWP Control Web Panel

CWP Control Web Panel (formerly CentOS Web Panel), a free hosting control panel used on CentOS/RHEL servers, contains an OS command injection flaw (CWE-78) in its handling of the login parameter. Because user-supplied login input reaches a shell without proper escaping, a remote attacker can submit shell metacharacters and have arbitrary operating-system commands executed on the hosting server. Successful exploitation yields command execution with the privileges of the panel (typically root-level on hosted servers), enabling full server takeover, data theft, or follow-on malware deployment. Any deployment running CWP Control Web Panel is affected, with the highest risk on servers whose panel login interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-01-17 and carries the maximum EPSS score (100% probability of exploitation within 30 days, 100th percentile), indicating active exploitation; no public PoC is known, the ransomware link is unconfirmed, and CVSS has not yet been scored.

Do: Update CWP Control Web Panel to the latest release per vendor instructions, consistent with the CISA KEV required action, and verify the patched build is running on every web-facing server. Until patched, restrict access to the CWP panel interface to trusted source IPs at the firewall and review logs for login requests containing shell metacharacters. As a KEV entry added 2023-01-17, federal agencies are required to remediate within the BOD 22-01 two-week window.

9.8100% KEV PoC ×6
  • CWP Control Web Panel (formerly CentOS Web Panel)
largeon the order of 10,000-100,000 internet-exposed CWP servers
Full article464 words · extracted from securityaffairs.com · click to collapse

A threat actor known as CrystalRay targeted 1,500 victims since February using tools like SSH-Snake and various open-source utilities.

The Sysdig Threat Research Team (TRT) first spotted the threat actor CrystalRay on February 2024 and observed it using the SSH-Snake open-source software penetration testing tool.

The experts collected new evidence that revealed that the threat actor expanded its operations.

The group’s operations have scaled 10x to over 1,500 victims, the threat actor now conducts mass scanning, exploits multiple vulnerabilities, and places backdoors using multiple open-source security tools (i.e. zmap, asn, httpx, nuclei, platypus, and SSH-Snake). 

CRYSTALRAY focuses on collecting and selling credentials, deploying cryptominers, and maintaining persistence in victim environments.

“CRYSTALRAY uses a lot of tools from the legitimate OSS organization, ProjectDiscovery. They include a package manager called pdtm to manage and maintain their open source tools which the attacker also uses.” reads the report published by Sysdig. “ProjectDiscovery has created a number of tools which we will see CRYSTALRAY abuse in their operations.”

The threat actor targets IP ranges in specific countries with more precision than a botnet, over 54% of the known targets are in the United States and China. The attackers use the ASN tool for reconnaissance, querying Shodan for data about targets without direct interaction. The group gathers information on open ports, vulnerabilities, and software/hardware details. They also generate IPv4/IPv6 CIDR blocks for specific countries using data from Marcel Bischoff’s country-ip-blocks repository.

The group was observed using Zmap for port scanning and the tool Nuclei as a vulnerability scanner.

The attacker was observed attempting to discover a variety of services, including Activemq, Confluence, Metabase, Weblogic, Solr, Openfire, Rocketmq, and Laravel. The scan aimed to identify and potentially exploit these services, indicating a broad and opportunistic approach to finding vulnerabilities across different platforms (i.e. CVE-2022-44877CVE-2021-3129, and CVE-2019-18394).

“Researchers discovered the dashboard CRYSTALRAY used to manage their victims based on an open source tool called Platypus, a modern multiple reverse shell sessions/clients web-based manager written in go.” continues the report.

The group deployed a payload generated using the open source cross-platform adversary emulation/red team framework Silver to maintain persistence and managed victims with the tool Platypus. CrystalRay sold harvested credentials on black markets. The attackers were also spotted deploying cryptominers on the target systems.

“CRYSTALRAY is a new threat actor who prefers to use multiple OSS tools to perform widespread vulnerability scanning and exploitation. Once they gain access, they install one of several backdoors to keep control of the target. SSH-snake is then used to spread throughout a victim’s network and collect credentials to sell.” Sysdig concludes. “Cryptominers are also deployed to gain further monetary value from the compromised assets.”

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, cybercrime)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/165607/cyber-crime/crystalray-operations-scaled-10x.html