Chinese APT IronHusky use Win zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-3309 | Privilege Escalation in Microsoft Windows Kernel (CVE-2016-3309) CVE-2016-3309 is a privilege escalation vulnerability in the Microsoft Windows kernel caused by improper handling of objects in memory. Triggering it typically requires getting crafted code to run on the system (the usual pattern for kernel EoP flaws), after which the kernel mishandles the objects and the attacker can execute arbitrary code in kernel mode. Successful exploitation grants full system-level privileges, letting an attacker disable security tooling, steal credentials, and deploy payloads such as ransomware. CISA lists the affected product broadly as Microsoft Windows, with older and legacy Windows builds being the most likely remaining targets for this 2016-era flaw. Exploitation is confirmed in the wild: the flaw was added to the CISA KEV catalog on 2022-03-15 with known ransomware use, and EPSS assigns a 20.6% probability of exploitation in the next 30 days (97th percentile). Do: Apply Microsoft's kernel-mode security updates per vendor instructions on all Windows systems, prioritizing legacy/out-of-support builds where this flaw is most likely to remain unpatched. Since the bug is KEV-listed with known ransomware use, verify patch deployment fleet-wide and inventory any Windows hosts that can no longer receive updates, isolating them or applying compensating controls. There is no public PoC, but treat unpatched Windows endpoints with local user or execution access as high priority for remediation. | 7.8 | 21% | KEV ransomware |
| masswell over 1,000,000 Windows installations broadly in scope (Windows runs on hundreds of millions of devices), with an unquantified but likely large tail of… | |
| CVE-2021-40449 | Use-After-Free Local Privilege Escalation in Microsoft Windows Win32k Microsoft's Win32k kernel driver contains a use-after-free (CWE-416) local privilege escalation vulnerability (CVE-2021-40449) affecting Windows client versions from Windows 7 through Windows 11 21H2. A local attacker who can already execute code on a system can trigger the flaw — demonstrated in a public proof of concept via the NtGdiResetDC system call — to corrupt kernel memory and elevate to SYSTEM-level privileges with high impact on confidentiality, integrity, and availability (CVSS 7.8, local vector, no user interaction). Any Windows desktop or laptop running the affected versions is exposed to any unprivileged process or malware that gains a foothold on the device. The bug was exploited as a zero-day in the wild before being fixed; CISA added it to the KEV catalog on 2021-11-17 with known ransomware use, and public reporting ties exploitation to the MysterySnail RAT campaign (including the lightweight MysteryMonoSnail backdoor). EPSS places the flaw in the 99th percentile, with a 74.1% probability of exploitation activity within 30 days. Do: Apply Microsoft's security updates addressing this Win32k flaw via Windows Update on all affected Windows 7, 8.1, 10, and 11 clients, per the CISA KEV required action, and verify inventories show no unpatched Windows 10 builds (1507–21H1) or Windows 11 21H2 endpoints. Because this was a zero-day exploited in the wild — including in campaigns involving MysterySnail and ransomware use noted by CISA — treat patching as urgent on all endpoints. Until patched, limit execution of untrusted or unprivileged local code on these systems. | 7.8 | 74% | KEV ransomware PoC |
| mass≈1 billion+ Windows client devices (effectively the entire Windows 7 through Windows 11 installed base at the time of disclosure) |
Full article421 words · extracted from securityaffairs.com · click to collapse

A Chinese-speaking hacking group exploited a Windows zero-day vulnerability in a wave of attacks on defense and IT businesses.
A Chinese-speaking hacking group exploited a zero-day vulnerability in the Windows Win32k kernel driver to deploy a new remote access trojan (RAT), tracked as MysterySnail.
The attacks were conducted between late August and early September 2021 and aimed at companies in the defense industry and IT firms. Kaspersky researchers found reported multiple attacks on Microsoft servers leveraging a zero-day exploit.
“In late August and early September 2021, Kaspersky technologies detected attacks with the use of an elevation of privilege exploit on multiple Microsoft Windows servers. The exploit had numerous debug strings from an older, publicly known exploit for vulnerability CVE-2016-3309, but closer analysis revealed that it was a zero-day.” reported the analysis published by Kaspersky.
The vulnerability is a use-after-free issue in the Win32k kernel driver, tracked as CVE-2021-40449, that was addressed by Microsoft with the release of October Patch Tuesday security updates.
The researchers analyzed the RAT employed in the attack and found code similarity and re-use of C2 infrastructure that allowed them to link the operation to a Chinese-speaking APT group known as IronHusky.
The IronHusky APT has been active at least since 2017 when the group was spotted targeting Russian and Mongolian government entities, aviation companies, and research institutes.
The elevation of privilege exploit used in the latest attacks, supports the following Windows products:
- Microsoft Windows Vista
- Microsoft Windows 7
- Microsoft Windows 8
- Microsoft Windows 8.1
- Microsoft Windows Server 2008
- Microsoft Windows Server 2008 R2
- Microsoft Windows Server 2012
- Microsoft Windows Server 2012 R2
- Microsoft Windows 10 (build 14393)
- Microsoft Windows Server 2016 (build 14393)
- Microsoft Windows 10 (build 17763)
- Microsoft Windows Server 2019 (build 17763)
The MysterySnail RAT analyzed by the researcher was uploaded to VT on August 10, 2021, experts noticed that it is very big (8.29MB) due to the presence of two very large functions that only waste processor clock cycles.
The RAT is not very sophisticated, however it implements 20 commands, including killing processes, managing files, spawning processes, operating proxy connections.
“The malware itself is not very sophisticated and has functionality similar to many other remote shells. But it still somehow stands out, with a relatively large number of implemented commands and extra capabilities like monitoring for inserted disk drives and the ability to act as a proxy.” concludes Kaspersky.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Windows)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/123285/hacking/ironhusky-zero-day.html