Carberp: it’s not over yet
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2010-0188 | Arbitrary Code Execution in Adobe Reader and Acrobat via Malicious PDF Handling CVE-2010-0188 is an unspecified code-injection (CWE-94) flaw in Adobe Reader and Acrobat that allows attackers to cause a denial of service or possibly execute arbitrary code on the victim's machine. It is triggered when an affected application processes a maliciously crafted PDF document, typically delivered as an email attachment or downloaded from a website, so simply viewing the file with vulnerable software is enough to expose the user. A successful attack gives the attacker code execution in the context of the logged-on user, which can be leveraged to install malware or ransomware. Anyone running Adobe Reader or Acrobat is affected; CISA lists the products without published version ranges, so all Adobe deployments should be treated as potentially in scope. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-03-03) with known ransomware use, and EPSS assigns an 88.2% probability of exploitation within 30 days (100th percentile). Do: Apply updates per vendor instructions: install the Adobe security update that fixes CVE-2010-0188 on any legacy Acrobat/Reader deployment and migrate unsupported installations to a currently supported Acrobat/Reader release. Given the known ransomware association, hunt for signs of compromise such as suspicious PDF attachments opened around malware activity, and block or sandbox PDFs at email and web gateways. Verify no critical hosts or automated workflows still depend on outdated Reader/Acrobat components for PDF processing. | — | 88% | KEV ransomware |
| masshundreds of millions of installed copies (Reader/Acrobat historically shipped as the default PDF handler on most Windows PCs; exact count of still-vulnerable… | |
| CVE-2011-3544 | Remote Code Execution in Oracle Java SE JRE Applet Rhino Script Engine CVE-2011-3544 is an access control flaw in the Rhino JavaScript Script Engine component used by Java applets in Oracle's Java Runtime Environment. It is triggered when a user's browser loads a malicious Java applet, allowing script executed through the Rhino engine to bypass Java's access restrictions. An attacker who successfully exploits it gains the ability to run arbitrary code on the victim's machine with the privileges of the logged-in user, typically via drive-by download from a compromised or attacker-controlled website. Any system with a vulnerable Oracle Java SE JDK or JRE and an enabled Java browser plugin is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-03-03, carries a 96.7% EPSS probability of exploitation within 30 days, and contemporary reports show it weaponized in the BlackHole/Whitehole exploit kits and used in mass OS X exploitation. Do: Apply updated Oracle Java SE builds per Oracle's vendor instructions, prioritizing internet-facing and end-user systems listed in the KEV guidance. Where patching is delayed, disable the Java browser plugin or block Java applets at the web gateway, since the attack vector is malicious applets served over the web. Review endpoints for signs of exploit-kit drive-by compromise, especially legacy Windows and OS X machines with outdated Java. | — | 97% | KEV |
| masshundreds of millions of desktops and servers with a Java runtime installed; exact count unknown |
Full article555 words · extracted from securelist.com · click to collapse
On 20 March, Russian law enforcement agencies announced the arrest of a cybercriminal gang involved in stealing money using the Carberp Trojan. This is very good news, but unfortunately does not mark the end of the Carberp story.
Evidently, those arrested were just one of the criminal gangs using the Trojan. At the same time, those who actually developed Carberp are still at large, openly selling the Trojan on cybercriminal forums.
Here is a recent offer for the ‘multifunctional bankbot’, which appeared on 21 March:
A post advertising the sale of Carberp
There are still numerous ‘affiliate programs’ involved in the distribution of Carberp, particularly “traffbiz.ru”.
We detected a new Carberp distribution incident on 21 March. Infection was initiated at radio-moswar.ru, a website devoted to the MosWar online browser game.
The main page of radio-moswar.ru
A page on the site includes a script which quietly redirects visitors to a web page in a third-level domain.
The script redirecting users from radio-moswar.ru
The second-level domain belongs to Dyn – a company that offers free services for the creation of free *.dyndns.TLD third-level domains. Such services are popular among cybercriminals as they make it unnecessary to register new domains.
Screenshot of the dyndns.tv website
A series of redirects to different DynDns domains ultimately leads to a script of the traffbiz affiliate program. Officially, the program acts as an intermediary between webmasters and traffic buyers, but according to our information, it is mostly used by cybercriminals to distribute malware.
Screenshot of the traffbiz.ru website
A script generates the hit counter image that is demonstrated to users. The script also includes two iframes which quietly redirect users to two links.
The hit counter code on traffbiz.ru
One of the links leads to Java (CVE-2011-3544) and PDF (CVE-2010-0188) exploits that download Trojan-Spy.Win32.Carberp.epm to the victim machine and launch it.
The Trojan attempts to connect to the command server by sending requests to three domains:
****case-now.com
****ssunrise.com
****owfood-cord.com
Curiously, according to whois data, these domains were registered on 20 March:

Curiously, according to whois data, these domains were registered on 20 March.
The command server to which Carberp connects is operational. It sends the command to the bot to download configuration files specifying which information the bot should steal and how. During the attack, Carberp intercepts the content of Citibank and Raiffeisen Bank webpages on the computer, as well as pages that use software created by BSS, a company which develops and deploys automated remote banking systems.
The second link leads to the infamous BlackHole Exploit Pack, which downloads and launches two malicious programs: a version of Carberp (Trojan-Spy.Win32.Carberp.epl) and a password-stealing Trojan (Trojan-PSW.Win32.Agent.acne).
Carberp also connects to a server located in Germany which has a different IP address. The domain name ****ltd.info was registered on 21 March:

The command center is operational but is not sending any commands as yet. The Trojan receives a list of plugins from that server.
The second piece of malware installed by the BlackHole Exploit Pack is designed to steal sensitive user data, such as FTP passwords. In addition, the Trojan modifies the hosts file to redirect users from vkontakte.ru and narod.ru sites to malicious servers.
In short, those responsible for developing Carberp remain at large and the cybercriminal gangs using the Trojan remain active. In other words, victory is a long way off.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/carberp-its-not-over-yet-2/32036/