ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Chinese Hackers Targeting South American Diplomatic Entities with ShadowPad

criticalVulnerabilityimportance 60CVE-2022-29464

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-29464
Unrestricted file upload leading to unauthenticated RCE in multiple WSO2 products

CVE-2022-29464 is an unrestricted file upload flaw (CISA classifies it as CWE-22, path traversal) in multiple WSO2 products — including WSO2 API Manager, Identity Server (and its Analytics and as-Key-Manager variants), and Enterprise Integrator — that lets an attacker write arbitrary files, such as JSP webshells, to any location on the server. It is triggered by sending crafted multipart upload requests to the WSO2 Carbon management-console file-upload endpoints, where directory traversal in the upload path allows files to be planted in the web root; requesting the uploaded file then executes it as code. An attacker who can reach a vulnerable management console gains unauthenticated remote code execution with the privileges of the WSO2 server process, which is often root in containerized deployments, enabling webshells, lateral movement, and ransomware staging. Any organization running affected WSO2 releases is exposed, especially where Identity Server (SSO/IAM) or API Manager gateways are internet-facing; the exact affected version ranges are enumerated in the WSO2 vendor advisory. Exploitation is confirmed: CISA added the flaw to the KEV catalog on 2022-04-25 with known ransomware use, and EPSS assigns a roughly 100% probability of exploitation within 30 days, making patching urgent.

Do: Apply the WSO2 updates/patches listed in the WSO2 security advisory for CVE-2022-29464 (or upgrade to the fixed releases named there), per CISA's required action, and limit internet exposure of Carbon management consoles in the meantime. Because ransomware groups have exploited this flaw, hunt for compromise: check web roots for unexpected JSP files or webshells and review access logs for suspicious file-upload requests followed by GETs to uploaded files.

9.8100% KEV ransomware PoC ×2
  • WSO2
largeon the order of tens of thousands of internet-exposed WSO2 management consoles (roughly 10,000–100,000 systems); total deployments including internal installs…
Full article418 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 14, 2023Cyber Threat Intelligence

Microsoft on Monday attributed a China-based cyber espionage actor to a set of attacks targeting diplomatic entities in South America.

The tech giant's Security Intelligence team is tracking the cluster under the emerging moniker DEV-0147, describing the activity as an "expansion of the group's data exfiltration operations that traditionally targeted government agencies and think tanks in Asia and Europe."

The threat actor is said to use established hacking tools such as ShadowPad to infiltrate targets and maintain persistent access.

ShadowPad, also called PoisonPlug, is a successor to the PlugX remote access trojan and has been widely put to use by Chinese adversarial collectives with links to the Ministry of State Security (MSS) and People's Liberation Army (PLA), per Secureworks.

One of the other malicious tools utilized by DEV-0147 is a webpack loader called QuasarLoader, which allows for deploying additional payloads onto the compromised hosts.

Redmond did not disclose the method DEV-0147 might be using to gain initial access to a target environment. That said, phishing and opportunistic targeting of unpatched applications are the likely vectors.

"DEV-0147's attacks in South America included post-exploitation activity involving the abuse of on-premises identity infrastructure for recon and lateral movement, and the use of Cobalt Strike for command-and-control and data exfiltration," Microsoft said.

DEV-0147 is far from the only China-based advanced persistent threat (APT) to leverage ShadowPad in recent months.

In September 2022, NCC Group unearthed details of an attack aimed at an unnamed organization that abused a critical flaw in WSO2 (CVE-2022-29464, CVSS score: 9.8) to drop web shells and activate an infection chain that led to the delivery of ShadowPad for intelligence gathering.

ShadowPad has also been employed by unidentified threat actors in an attack targeting an ASEAN member foreign ministry through the successful exploitation of a vulnerable, and Internet-connected, Microsoft Exchange Server.

The activity, dubbed REF2924 by Elastic Security Labs, has been observed to share tactical associations with those adopted by other nation-state groups such as Winnti (aka APT41) and ChamelGang.

"The REF2924 intrusion set [...] represents an attack group that appears focused on priorities that, when observed across campaigns, align with a sponsored national strategic interest," the company noted.

The fact that Chinese hacking groups continue to use ShadowPad despite it being well-documented over the years suggests the technique is yielding some success.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/02/chinese-hackers-targeting-south.html