China-linked actors hacked US Treasury Department
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-12356 | Unauthenticated Command Injection in BeyondTrust Privileged Remote Access/Remote Support BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an unauthenticated command injection flaw (CWE-77) that allows a remote attacker to inject commands that are executed as a site user. The vulnerability is network-facing with low attack complexity and requires no privileges or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), so any attacker who can reach the affected PRA/RS interface can trigger it. Successful exploitation yields arbitrary command execution in the context of the site user, with high impact ratings for confidentiality, integrity, and availability. Any organization running BeyondTrust PRA or RS — particularly where those remote-access/remote-support services are exposed to the internet — is affected; the available data does not specify affected version ranges. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-19, carries an 88% EPSS probability of exploitation within 30 days (100th percentile), and was reportedly used in the breach of the U.S. Treasury alongside a PostgreSQL vulnerability. Do: Apply BeyondTrust's patches or vendor-specified mitigations immediately — remediation is mandatory for U.S. federal agencies under the KEV listing, and the source data does not include fixed build numbers, so confirm the correct upgrade version in BeyondTrust's security bulletin. As an interim measure, restrict or remove internet exposure of PRA/RS endpoints and hunt for signs of exploitation (unexpected commands executed as the site user), noting this flaw was used in the U.S. Treasury intrusion. If mitigations are unavailable, CISA's required action is to discontinue use of the product. | 9.8 | 88% | KEV PoC |
| moderate≈ a few thousand internet-exposed PRA/RS instances (order-of-magnitude estimate from public internet scans) | |
| CVE-2024-12686 | OS Command Injection in BeyondTrust Privileged Remote Access and Remote Support CVE-2024-12686 is an OS command injection flaw (CWE-78) in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) that is reachable over the network but requires the attacker to already hold administrative privileges in the product. By injecting commands through an administrative function, the attacker gets arbitrary commands executed on the underlying host as the site user, producing high impact to confidentiality, integrity, and availability in that context. Organizations running BeyondTrust PRA or RS — commonly deployed for privileged remote support and help-desk access — are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-13, confirming exploitation in the wild, and EPSS assigns a 13.8% probability of exploitation within 30 days (96th percentile). The flaw arrives amid a broader wave of BeyondTrust attacks, including the related zero-day CVE-2024-12356 tied to a compromised API key that exposed 17 SaaS customers and was used by a China-linked actor against U.S. Treasury systems, and reported chaining with a PostgreSQL flaw in targeted attacks. Do: Upgrade all PRA and RS deployments to the fixed releases identified in BeyondTrust's security bulletin for CVE-2024-12686 (including any SaaS instances managed by BeyondTrust), and apply the mitigations required by the CISA KEV entry if patching must be deferred. Because exploitation requires administrative access, review and rotate privileged and API credentials — especially given the related API-key compromise behind CVE-2024-12356 — restrict administrative console exposure to trusted networks, and check logs for unexpected commands executed as the site user. | 7.2 | 14% | KEV |
| moderatelikely on the order of thousands of exposed PRA/RS instances (estimate; no install counts in source data) |
Full article349 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 31, 2024

China-linked threat actors breached the U.S. Treasury Department by hacking a remote support platform used by the agency.
China-linked threat actors breached the U.S. Treasury Department via a compromised remote support platform. The Treasury Department discovered the security breach on December 8th from its vendor BeyondTrust, according to a letter to lawmakers.
BeyondTrust provides Privileged Access Management and secure remote access, serving sectors like government, healthcare, banking, and energy.
Early this month, the privileged access management company BeyondTrust suffered a cyberattack after threat actors breached some of its Remote Support SaaS instances.
The Treasury Department is investigating the incident with the help of the F.B.I., and the intelligence community.
The threat actors gained access to the workstations of government employees and unclassified documents.
“In a letter informing lawmakers of the episode, the Treasury Department said that it had been notified on Dec. 8 by a third-party software service company, BeyondTrust, that the hacker had obtained a security key that allowed it to remotely gain access to certain Treasury workstations and documents on them.” reported the New York Times.
“Based on available indicators, the incident has been attributed to a China state-sponsored Advanced Persistent Threat (APT) actor,” the letter said. “In accordance with Treasury policy, intrusions attributable to an APT are considered a major cybersecurity incident.”
The US Agency has taken the breached service offline and logged out the intruders.
The Treasury Department plans to report breach details to Congress, while the Chinese government denies involvement and promotes cybersecurity cooperation.
The investigation into the cyberattack against BeyondTrust led to the discovery of the zero-day vulnerabilities CVE-2024-12356 and CVE-2024-12686. Threat actors exploited the flaws to take over Remote Support SaaS instances, including the Treasury Department’s one.
On December 20, 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection flaw, tracked as CVE-2024-12356 (CVSS score of 9.8) to its Known Exploited Vulnerabilities (KEV) catalog.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Treasury Department)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172482/intelligence/china-hacked-u-s-treasury-department.html