Cyber-espionage group Cloud Atlas targets Russian companies with war
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-11882 | Memory Corruption RCE in Microsoft Office via Legacy Equation Editor CVE-2017-11882 is a memory corruption vulnerability (CWE-119) in Microsoft Office, residing in the legacy Microsoft Equation Editor component (EQNEDT32.EXE), that allows remote code execution in the context of the current user. Attackers trigger it by persuading a user to open a crafted document, most commonly an RTF file or other Office document carrying a malicious embedded equation object, which overflows a buffer while the equation content is parsed. Successful exploitation lets the attacker run arbitrary code with the privileges of the signed-in user, a typical foothold for malware delivery and, per CISA, for ransomware operations. Any environment running affected Microsoft Office builds is exposed; the source data does not enumerate specific affected version ranges. The flaw is confirmed exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and holds a 99.9% EPSS score (percentile 100), though the source data lists no public PoC. Do: Apply Microsoft's Office security updates (November 2017 or later) across all endpoints, prioritizing this KEV-listed flaw given its known ransomware use. On systems that cannot yet be patched, disable or unregister the legacy Equation Editor (EQNEDT32.EXE) and consider blocking or warning on RTF attachments as interim mitigations. Check for indicators of abuse such as EQNEDT32.EXE spawning unexpected child processes after document opens. | 7.8 | 100% | KEV ransomware PoC ×10 |
| masshundreds of millions of users/installations (Office is near-ubiquitous on Windows and in enterprises; the share still unpatched is unknown) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | mail.ru | egistered on popular Russian email services — yandex.ru and mail.ru. The emails contained malicious attachments that, once open |
| domain | yandex.ru | il addresses registered on popular Russian email services — yandex.ru and mail.ru. The emails contained malicious attachments tha |
Full article490 words · extracted from therecord.media · click to collapse
The hacker group known as Cloud Atlas targeted a Russian agro-industrial enterprise and a state-owned research company in a new espionage campaign, researchers have found. Cloud Atlas is a state-backed threat actor, active since at least 2014, that mostly attacks organizations in Russia, Belarus, Azerbaijan, Turkey, and Slovenia. In its new campaign, the hackers sent their victims phishing emails with malicious attachments — the tactic they were seen using in previous attacks, according to the Russian cybersecurity firm F.A.C.C.T., an offshoot of the Singapore-based cybersecurity firm Group IB. The researchers said that two attacks they detected were successfully blocked. In the report released earlier this week, F.A.C.C.T. published examples of two phishing letters discovered while analyzing the attacks. The first email offered to send postcards to soldiers fighting in the war in Ukraine and their family members. Both the report and the malicious emails referred to the war as “SVO” (special military operation), a term used by the Kremlin to describe its invasion of Ukraine. The second email was related to changes in the law regarding military reserves. Both letters were sent from email addresses registered on popular Russian email services — yandex.ru and mail.ru. The emails contained malicious attachments that, once opened, uploaded files with an exploit for the vulnerability known as CVE-2017-11882. This is a vulnerability in Microsoft Office that was fixed back in 2017 but is still actively exploited. Successful exploitation of this bug allows attackers to execute arbitrary code with the privileges of the user who opened the malicious file. Thus, if the victim has administrator rights, the attacker will be able to take full control of their system — install programs, view, modify, or destroy data, and even create new accounts, said researchers at Moscow-based Kaspersky. Last December, researchers at Check Point published a report saying that Cloud Atlas ramped up activities targeting “high profile victims” in Russia, Belarus, Transnistria (a pro-Kremlin breakaway region of Moldova), and Russian-annexed territories of Ukraine, including Crimea, Luhansk, and Donetsk. Cloud Atlas focuses on espionage and theft of confidential information, but it isn’t clear what country sponsors the group. The hackers typically use phishing emails with malicious attachments to gain initial access to a victim’s computer. These documents are carefully crafted to mimic government statements, media articles, business proposals, or advertisements, researchers said. The attackers closely control who can access their malicious attachments by whitelisting the targets. To collect the IP information of the victims, Cloud Atlas first sent them reconnaissance documents, which do not contain any malicious files aside from fingerprinting the victim, according to Check Point.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cloud-atlas-targets-russian-orgs-war-phishing