ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Bitter APT Hackers Continue to Target Bangladesh Military Entities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0798
Memory Corruption RCE in Microsoft Office Equation Editor (CVE-2018-0798)

CVE-2018-0798 is a memory corruption flaw (out-of-bounds write, CWE-787) in the Microsoft Equation Editor component of Microsoft Office 2007, 2010, 2013, and 2016 that allows remote code execution when the component mishandles objects in memory. A remote attacker triggers it by persuading a user to open a specially crafted document containing a maliciously embedded equation; user interaction is required and no privileges are needed (CVSS vector AV:N/AC:L/PR:N/UI:R). Successful exploitation lets the attacker run arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Any organization running the affected legacy Office versions — including deployments using the Office Compatibility Pack — is exposed, with government, military, and transportation organizations named in related reporting on Office-document attack campaigns. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and its EPSS score of 95.1% (100th percentile) indicates a very high probability of active exploitation, with related headlines highlighting APT activity (notably the Bitter group's campaigns against military targets in South Asia) around Office document threats.

Do: Apply Microsoft's security updates for this vulnerability across Office 2007, 2010, 2013, 2016 and the Office Compatibility Pack, per vendor instructions as required by CISA KEV, and upgrade off legacy Office 2007/2010 to a still-supported release since those versions no longer receive regular fixes. Enforce caution with untrusted Office documents (don't open unsolicited attachments or embedded equations from unknown sources) and consider stripping or blocking embedded OLE equation objects from external files. Prioritize patching for government, military, and transportation-sector environments given active APT targeting of those sectors via Office documents.

8.895% KEV
  • Microsoft Office (Equation Editor) Office 2007, Office 2010, Office 2013, Office 2016
  • Microsoft Office Compatibility Pack
  • Microsoft Word
masshundreds of millions of Office users/endpoints worldwide
Full article388 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 06, 2022

Military entities located in Bangladesh continue to be at the receiving end of sustained cyberattacks by an advanced persistent threat tracked as Bitter.

"Through malicious document files and intermediate malware stages the threat actors conduct espionage by deploying Remote Access Trojans," cybersecurity firm SECUINFRA said in a new write-up published on July 5.

The findings from the Berlin-headquartered company build on a previous report from Cisco Talos in May, which disclosed the group's expansion in targeting to strike Bangladeshi government organizations with a backdoor called ZxxZ.

Bitter, also tracked under the codenames APT-C-08 and T-APT-17, is said to be active since at least late 2013 and has a track record of targeting China, Pakistan, and Saudi Arabia using different tools such as BitterRAT and ArtraDownloader.

The latest attack chain detailed by SECUINFRA is believed to have been conducted in mid-May 2022, originating with a weaponized Excel document likely distributed by means of a spear-phishing email that, when opened, exploits the Microsoft Equation Editor exploit (CVE-2018-0798) to drop the next-stage binary from a remote server.

ZxxZ (or MuuyDownloader by the Qi-Anxin Threat Intelligence Center), as the downloaded payload is called, is implemented in Visual C++ and functions as a second-stage implant that allows the adversary to deploy additional malware.

The most notable change in the malware involves abandoning the "ZxxZ" separator used when sending information back to the command-and-control (C2) server in favor of an underscore, suggesting that the group is actively making modifications to its source code to stay under the radar.

Also put to use by the threat actor in its campaigns is a backdoor dubbed Almond RAT, a .NET-based RAT that first came to light in May 2022 and offers basic data gathering functionality and the ability to execute arbitrary commands. Additionally, the implant employs obfuscation and string encryption techniques to evade detection and to hinder analysis.

"Almond RATs main purposes seem to be file system discovery, data exfiltration and a way to load more tools/establish persistence," the researchers said. "The design of the tools seems to be laid out in a way that it can be quickly modified and adapted to the current attack scenario."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/07/bitter-apt-hackers-continue-to-target.html