ZeroHour
Infosecurity Magazinepublished ()ingested James Coker

Sandworm Linked to Attack on Danish Critical Infrastructure

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-28771
Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls

CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies.

Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use.

9.899% KEV PoC
  • Zyxel ZyWALL/USG series firewalls firmware 4.60 through 4.73
  • Zyxel VPN series firewalls firmware 4.60 through 5.35
  • Zyxel USG FLEX series firewalls (USG FLEX 50, 50W, 100, 100W, 200, 500) firmware 4.60 through 5.35
  • +1 more
largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate
CVE-2023-33010
+1 in the same advisory: …33009
Buffer Overflow in Zyxel ATP, USG FLEX, VPN and ZyWALL/USG Firewalls Enables RCE

CVE-2023-33010 is a buffer overflow (CWE-120) in the ID processing function of Zyxel's firewall firmware that is triggered when an affected device processes crafted input sent by an unauthenticated attacker. Successful exploitation can cause denial-of-service conditions and, more seriously, allow remote code execution on the firewall itself, giving an attacker a foothold at the network perimeter. The flaw affects multiple Zyxel firewall lines widely used by small and mid-sized organizations, including ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and legacy ZyWALL/USG models. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog (added 2023-06-05), indicating it is being exploited in the wild, though no public proof-of-concept is known and ransomware association is unconfirmed. EPSS puts the 30-day exploitation probability at 28.8% (98th percentile), and no CVSS score has been published yet.

Do: Apply the updated firmware for your specific model per Zyxel's security advisory, since the CISA required action is to patch per vendor instructions. Until patched, restrict or disable WAN-side access to the firewall's management/ID processing interfaces and monitor devices for signs of compromise such as unexpected reboots or crashes. Inventory all ATP, USG FLEX (including 50(W)), USG20(W)-VPN, VPN, and ZyWALL/USG units to confirm none remain unpatched.

9.829% KEV
  • Zyxel ATP series firewalls
  • Zyxel USG FLEX firewalls
  • Zyxel USG FLEX 50(W) firewalls
  • +3 more
large≈tens of thousands of internet-exposed devices from a combined installed base likely well over 100,000 across these firewall lines
Full article745 words · extracted from infosecurity-magazine.com · click to collapse

Notorious Russian nation-state threat actor Sandworm has been linked to the largest ever cyber-attack targeting critical infrastructure in Denmark.

The incident took place in May 2023 and saw the attackers targeted 22 companies involved in operating Danish critical infrastructure, according to SektorCERT, a non-profit that helps protect organizations in this sector.

SektorCERT found evidence connecting some of these attacks to Sandworm, a group thought to operate under the Russian intelligence agency GRU. Sandworm was behind the attacks that took down power in parts of Ukraine in 2015 and 2016.

The group has also been blamed for more recent cyber-attacks on critical infrastructure in Ukraine, which have been coordinated with Russian military action in the region.

SektorCERT said that in its three years of existence, it had never previously seen signs that nation-state groups have targeted Danish critical infrastructure.

A Two-Phased Attack Leveraging Zyxel Vulnerabilities

In the first wave of attacks that began on May 11, the threat actors exploited the critical vulnerability CVE-2023-28771 contained in Zyxel firewalls, which are used by many Danish critical infrastructure companies.

This vulnerability was both relatively easy to exploit and could have major consequences, according to SektorCERT’s report on the incident. Oncee exploited, attackers were able to send network packets to a Zyxel firewall and gain complete control of it without knowing authentication information for the device.

The coordinated attack hit 16 “carefully selected targets” among Danish energy companies. Of these, 11 were compromised immediately, with the attackers executing code on the firewalls that caused them to hand their configuration and current usernames over.

The other five attacks failed due to the commands not being completed.

SektorCERT assembled an emergency incident response team that prevented the attackers exploiting the access they had gained to the 11 companies, and potentially affecting electricity and heat supplies.

A second wave of attacks took place from 22-25 May, using “never-before-seen cyber weapons.” It is likely the attacks were perpetrated by different groups, who may have colluded to carry out the attacks. 

"Not once did a shot miss the target. All attacks hit exactly where the vulnerabilities were”

It is thought this second wave of attacks exploited two new Zyxel vulnerabilities announced on May 24: CVE-2023-33009 and CVE-2023-33010.

“It was notable for these second-wave attacks that the attackers may have had knowledge of vulnerabilities that Zyxel had not yet disclosed,” added the report.

All organizations affected by this second wave of attacks were forced disconnect from the internet and go into “island mode.”

Additionally, the attackers used access to these firewalls to carry out DDoS attacks against separate targets, including in the US and Hong Kong.

As with the first wave of attacks, the threat actors were stopped before they were able to impact critical services.

After the exploit code for some of the vulnerabilities became publicly known on May 30, “attack attempts against Danish critical infrastructure exploded – especially from IP addresses in Poland and Ukraine,” the SektorCERT report noted. However, by this stage SektorCERT members had patched the vulnerabilities, meaning they were no longer vulnerable to such attacks.

Sophisticated Attacks Linked to Sandworm

The report said it was “remarkable” that so many companies were attacked at the same time, noting that an attack of this nature would require significant planning and resources.

“The attackers knew in advance who they wanted to hit. Not once did a shot miss the target. All attacks hit exactly where the vulnerabilities were,” it read.

While the attackers took steps to evade detection, SektorCERT analysts traced traffic from some of the attacks to IP addresses thought to belong to the Sandworm group.

“Whether Sandworm was involved in the attack cannot be said with certainty. Individual indicators of this have been observed, but we have no opportunity to neither confirm nor deny it,” stated the report.

Commenting on the story, Ted Miracco, CEO, Approov Mobile Security, said he was not surprised that the attacks were linked to Sandworm, with energy companies in many European countries that have supported Ukraine now major targets of Russian state-linked groups.

“With eyes now turned to the Middle East, we may see even more aggressive and increasingly sophisticated attacks on the Ukraine and its allies, as the Russians perhaps see support from the West potentially wavering or at least seeing signs of fatigue,” he said.

Miracco added: “Another take away from this incident is the short-sighted decision making that led to critical infrastructure providers not patching a known zero-day vulnerability in the Zyxel firewalls.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/russian-sandworm-attack-danish/